Εθνική Στρατηγική για την Τεχνητή Νοημοσύνη (ΤΝ) της Κυπριακής Δημοκρατίας
Υφυπουργείο Έρευνας, Καινοτομιας Και Ψηφιακής Πολιτικής
Ανακοινώνεται η έναρξη Δημόσιας Διαβούλευσης της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ), που εκπονήθηκε από την Εθνική Εξειδικευμένη Επιτροπή για την Τεχνητή Νοημοσύνη (National AI Taskforce), η οποία συστάθηκε με Απόφαση του Υπουργικού Συμβουλίου (αρ. απόφασης 97.538, ημερ. 22/1/2025), υπό την προεδρία του Επικεφαλής Επιστήμονα για Έρευνα, Καινοτομία και Τεχνολογία, και με έντεκα (11) μέλη προερχόμενα από τον δημόσιο και ιδιωτικό τομέα, την ακαδημαϊκή και ερευνητική κοινότητα.
Η Στρατηγική αποτελεί το ολοκληρωμένο εθνικό πλαίσιο πολιτικής της Κυπριακής Δημοκρατίας για την αξιοποίηση των δυνατοτήτων της ΤΝ, με όραμα, έως το 2032, η Κύπρος να αναγνωρίζεται ως ο αξιόπιστος κόμβος ΤΝ στην Ανατολική Μεσόγειο, ως μια αξιόπιστη ευρωπαϊκή δικαιοδοσία για την παροχή υπηρεσιών που αξιοποιούν την ΤΝ και ως γέφυρα μεταξύ της Ευρωπαϊκής Ένωσης και των γειτονικών περιοχών.
H Στρατηγική αναπτύσσεται γύρω από 8 αλληλένδετους Εθνικούς Στρατηγικούς Στόχους:
- Καθιέρωση της Κύπρου ως αξιόπιστης δικαιοδοσίας για την ΤΝ.
- Αύξηση της εθνικής παραγωγικότητας μέσω της υπεύθυνης υιοθέτησης της ΤΝ.
- Ανάπτυξη ενός ισχυρού και χωρίς αποκλεισμούς οικοσυστήματος ΤΝ.
- Μετασχηματισμό των δημόσιων υπηρεσιών μέσω της αξιοποίησης της ΤΝ.
- Ανάπτυξη, προσέλκυση και διατήρηση δεξιοτήτων και ανθρώπινου δυναμικού στον τομέα της ΤΝ.
- Διασφάλιση ασφαλών, κυρίαρχων και διαλειτουργικών δεδομένων και υποδομών.
- Εδραίωση ισχυρής διακυβέρνησης, δεοντολογίας και λογοδοσίας σε κάθε χρήση της ΤΝ.
- Ανάπτυξη κυρίαρχων εθνικών δυνατοτήτων μέσω στρατηγικών συνεργασιών.
Το προσχέδιο της Εθνικής Στρατηγικής για την ΤΝ βρίσκεται αναρτημένο πιο κάτω και καλούνται όλοι οι ενδιαφερόμενοι να υποβάλουν τα σχόλια, εισηγήσεις και παρατηρήσεις τους μέσω της πλατφόρμας «η-Διαβούλευση» μέχρι την 31η Αυγούστου 2026.
Όλες οι απόψεις και προτάσεις που θα υποβληθούν θα αξιολογηθούν και, όπου κριθεί σκόπιμο, θα ενσωματωθούν στην τελική έκδοση της Στρατηγικής.
Παράκληση όπως τα σχόλια γίνονται σύμφωνα με την πιο κάτω δομή:
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Σχόλιο / Εισήγηση
Αιτιολόγηση σχολίου / Εισήγησης
Για οποιεσδήποτε διευκρινίσεις σχετικά με τη διαδικασία της διαβούλευσης, μπορείτε να επικοινωνείτε με το Υφυπουργείο Έρευνας, Καινοτομίας και Ψηφιακής Πολιτικής.
- Υπό επεξεργασία
- Αναρτήθηκε
20 Ιούλ 2026 @ 0:00 - Ανοικτή σε σχόλια ως
31 Αυγ 2026 @ 23:50 - 128 σχόλια
Περιεχόμενα
| 01 - ΕΘΝΙΚΗ ΣΤΡΑΤΗΓΙΚΗ ΓΙΑ ΤΗΝ ΤΕΧΝΗΤΗ ΝΟΗΜΟΣΥΝΗ ΤΗΣ ΚΥΠΡΙΑΚΗΣ ΔΗΜΟΚΡΑΤΙΑΣ | 9 σχόλια |
ΣΑΙΕΕΚ
Ο ΣΑΙΕΕΚ είναι Σωματείο Αντιπροσώπων Ιατρικού και Επιστημονικού Εξοπλισμού Κύπρου, ιδρύθηκε το 1999 και περιλαμβάνει 50 και πλέον εταιρείες μέλη, που ασχολούνται με τους τομείς Ιατροτεχνολογικού, Αναλυτικού και Life Science εξοπλισμού και αναλωσίμων, εξυπηρετώντας τα Δημόσια και Ιδιωτικά Νοσηλευτήρια, Πανεπιστήμια, Ερευνητικά Κέντρα κλπ.
Πριν την κατάθεση των σχολίων μας, θα θέλαμε να συγχαρούμε την Εθνική Ομάδα Εργασίας για την Τεχνητή Νοημοσύνη και τον Επικεφαλής Επιστήμονα για την Έρευνα, την Καινοτομία και την Τεχνολογία για ένα εκτεταμένο και τεκμηριωμένο προσχέδιο Στρατηγικής, για το χρόνο που διέθεσαν να επικοινωνήσουν το όραμα και τη Στρατηγική και για την προθυμία τους να δηλώσουν τους περιορισμούς και τις φιλοδοξίες τους.
Τα χαρακτηριστικά που μας κέντρισαν την προσοχή και είναι ιδιαίτερα ευπρόσδεκτα είναι:
1. Human-Centric AI & Citizen Empowerment (“Technology for Citizens”)
2. Public Sector Modernization & Smart Governance
3. Research, Innovation & Commercial Ecosystem Development
4. Data Ecosystem, Infrastructure & Connectivity
5. Talent Acquisition & Workforce Transformation
Όντας εταιρείες που ασχολούμαστε με την Υγεία χαιρετίζουμε ότι θα υπάρξει Εθνική Στρατηγική για την ΤΝ, που ήδη εφαρμόζεται σε συστήματα νέας τεχνολογίας σε ευρή φάσμα της Ιατρικής. Στο σημείο αυτό θα πρέπει να τονιστεί ότι είναι αναγκαία η επιβολή τέτοιων συστημάτων, που μπορούν να επιταχύνουν τη διάγνωση των ασθενών και να κερδηθεί χρόνος και χρήματα στο σύστημα, διότι πρόωρη διάγνωση σημαίνει αποτελεσματικότερη και πιο σύντομη θεραπεία. Το κόστος αυτών των νέων τεχνολογιών μπορεί να φαίνεται αρχικά υψηλό, όμως αν συνυπολογιστούν τα οφέλη και η αποσυμφόρηση του ΓΕΣΥ είναι απόλυτα διαχειρίσιμο.
Σχόλιο 1: 1.5 Implementation Timeline and Success Metrics
Το χρονοδιάγραμμα όπως παρατίθεται είναι ιδιαίτερα φιλόδοξο, όταν προϋποθέτει εμπλοκή δημόσιων φορέων/δημόσιων λειτουργών κλπ.
Εισήγηση 1: Για να επιτευχθούν οι στόχοι εντός τόσο απαιτητικού χρονοδιαγράμματος, θα πρέπει να υπάρχει απόλυτος συντονισμός, πολιτική βούληση και επίβλεψη των στόχων σε Παγκύπριο επίπεδο. Αυτή τη στιγμή, όσον αφορά τον τομέα της Υγείας και συγκεκριμένα στα προϊόντα καταλόγου ΖC που χειρίζεται ο ΟΑΥ, υπάρχει καθυστέρηση εγκρίσεων νέων τεχνολογιών με ΤΝ ως και 5 χρόνια για ένταξη στο ΓΕΣΥ. Πως θα μπορούσε με διαφάνεια να βελτιωθεί η κατάσταση;
Σχόλιο 2: Healthcare and Life Sciences, p75
Η ΤΝ στον ιατρικό χώρο εμπίπτει σε αυστηρές νομοθεσίες και κανονισμούς (π.χ. Medical Device Regulation 2017/45)αλλά πρέπει να λαμβάνει υπόψη το ΕU AI Act και την επικείμενη ψήφιση του περί Τεχνητής Νοημοσύνης Νόμο του 2026.
Εισήγηση 2: Δημιουργία σαφών και διαφανών, fast-track διαδικασιών έγκρισης/ενσωμάτωσης στο σύστημα υγείας λογισμικών (από εταιρείες του εξωτερικού) και τεχνολογιών ΤΝ, διασφαλίζοντας την ασφάλεια δεδομένων, την πιστοποίηση και την κατανομή ευθύνης. Η υιοθέτηση τέτοιων λογισμικών από Νοσοκομεία/κλινικές, διαγνωστικά κέντρα και κλινικά εργαστήρια απαιτεί έξτρα επενδύσεις και θα πρέπει να δοθούν οικονομικά κίνητρα ή/και ειδικές αποζημιώσεις (π.χ. μέσω ΟΑΥ ή Υπουργείου Υγείας ή Ευρωπαϊκών κονδυλίων) για ιατρικές ή/και διαγνωστικές πράξεις που χρησιμοποιούν τεχνολογίες με ενσωμάτωση ΤΝ, οι οποίες μειώνουν το χρόνο, αυξάνουν την ακρίβεια, βελτιώνοντας έτσι την υπηρεσία στον Κύπριο ασθενή.
Σχόλιο 3: Κατηγοριοποίηση ιατροτεχνολογικού εξοπλισμού και ιατρικών αναλωσίμων με ΤΝ
Εισήγηση 3: Να καταρτιστούν συγκεκριμένες προϋποθέσεις που πρέπει να πληρούν ο ιατροτεχνολογικός εξοπλισμός ή/και αναλώσιμα για να μπορούν να κατηγοριοποιούνται ή/και να ονομάζονται ως είδη με ΤΝ, είτε είναι για επαγγελματική χρήση ή για προσωπική χρήση. Αν υπάρχουν διεθνή ή/και ευρωπαϊκά standards που καθορίζουν την κατηγοριοποίηση αυτή, να ενσωματωθούν στην Κυπριακή Εθνική Στρατηγική και Governance
Γενικές Θέσεις ΣΑΙΕΕΚ
1. Υιοθέτηση έτοιμων λύσεων
Θέση: Η Εθνική στρατηγική δεν πρέπει να εστιάζει μόνο στην έρευνα, αλλά στην άμεση εφαρμογή έτοιμων λύσεων, που προσφέρονται μέσω λογισμικών ΤΝ.
Στόχος: Αναγνώριση των μελών του ΣΑΙΕΕΚ ως των επίσημων φορέων που εισάγουν, παραδίδουν και υποστηρίζουν τεχνικά ώριμα πιστοποιημένα λογισμικά ΤΝ στην καθημερινή κλινική πράξη.
2. Συνεργασία με ομάδα Chief Scientist και ο θεσμικός ρόλος ΣΑΙΕΕΚ
Θέση: Επιθυμούμε ανάπτυξη της συνεργασίας μεταξύ της ομάδας του Chief Scientist κι άλλων κρατικών φορέων, ώστε ο ΣΑΙΕΕΚ να καταστεί το θεσμικό όργανο του ιδιωτικού τομέα και της βιομηχανίας για θέματα ΤΝ στον ιατρικό χώρο.
Στόχος: Ορισμός σημείου επαφής μεταξύ ΣΑΙΕΕΚ και της ομάδας για την Εθνική Στρατηγική για την ΤΝ, ώστε η γραπτή τοποθέτηση του Συνδέσμου στην πλατφόρμα e-consultation.gov.cy να αξιοποιηθεί ουσιαστικά.
3. Καμπάνια ενημέρωσης και επαγρύπνησης με τη συνδρομή του ΣΑΙΕΕΚ
Θέση: Πρέπει να υπάρξει καμπάνια επαγρύπνησης για τα οφέλη της ΤΝ, η οποία έρχεται να συνδράμει και όχι να αντικαταστήσει τον επιστήμονα, ο οποίος έχει τον τελικό λόγο και απόφαση.
Στόχος: Θα πρέπει και με τη συμβολή του ΣΑΙΕΕΚ να υπάρξουν ενημερώσεις στους διάφορους φορείς, που θα συμμετάσχουν στον εγχείρημα (ΟΑΥ, ΟΚΥΠΥ, ΥΥ), ώστε να μπορέσει να γίνει αντιληπτό το όφελος της εφαρμογής της Εθνικής Στρατηγικής για την ΤΝ.
It is suggested that the Research and Innovation focus areas be reviewed to consider the inclusion of Culture and Creativity as a dedicated Research Focus Area or strategic cross-cutting research domain. This could represent an area in which Cyprus has the potential to develop a distinctive position at European level. Cyprus already has a strong foundation on which to build, including an established creative and cultural ecosystem, a growing games and digital creative industries sector, and a solid base of researchers, technologists and experts. Bringing these capabilities together could create a strong environment for applied research and innovation at the intersection of AI, culture, creativity, digital heritage, gaming and immersive technologies. This direction is also increasingly aligned with EU research and innovation priorities. Initiatives such as the Culture Compass for Europe, Horizon Europe, the New European Bauhaus, EIT Culture & Creativity and S+T+ARTS increasingly recognise the convergence of culture, creativity, research and technology as an important driver of innovation, competitiveness and societal impact. Such a focus could also have a direct positive impact on tourism, by enabling the development of new cultural experiences, immersive heritage applications, AI-enhanced visitor experiences and innovative ways of presenting Cyprus’s cultural assets. In this way, investment in culture and creativity could also contribute to strengthening the competitiveness and attractiveness of Cyprus as a destination. Similarly, it could support the growth of the games industry by fostering the development and adoption of AI, immersive technologies, digital storytelling and creative technologies, while creating stronger links between research, talent and the emerging games and digital creative industries ecosystem in Cyprus.
It is suggested that, before considering the establishment of additional standalone Centres of Excellence, the Strategy explore the potential for a coordinated national structure that builds on and further strengthens the capabilities of Cyprus’s existing Centres of Excellence. Such a structure could take the form of a network, consortium or distributed Centre, bringing together existing teams, infrastructure, research expertise and industry-facing services under a common strategic and governance framework.
As a first step, a national mapping of available expertise, infrastructure and services could be undertaken to identify the capabilities already present within the ecosystem and determine any areas where genuine gaps remain. Where additional capacity is required, personnel, infrastructure or specialised units could potentially be developed within, or jointly across, the existing Centres.
Such an approach could also allow the Strategy to be implemented more rapidly, as many of the key experts and teams required to address the priority areas are already established within Centres of Excellence. The Centres have also established administrative and operational structures, as well as experience in recruiting additional personnel, which could facilitate the development of any additional capacity required within a relatively short timeframe. By comparison, a new standalone Centre would naturally require time to build its teams, infrastructure, operational structures and networks before reaching a comparable level of maturity.
There may also be significant opportunities to achieve greater cost-effectiveness by building on existing capabilities. Attracting a sufficient number of high-calibre senior experts to independently cover all the priority areas identified in the Strategy could be both costly and challenging. Many of these areas are already represented within the existing Centres, allowing a coordinated structure to leverage established expertise while focusing new investment on areas where additional capacity is genuinely needed.
The existing Centres could also provide a strong foundation for the industry-facing dimension of such a structure. They are already connected to major European and national initiatives, including the AI Factory Antenna and European Digital Innovation Hubs (EDIHs), and have established mechanisms, networks and experience for engaging with and supporting industry. Building on these existing structures could therefore facilitate a more immediate connection between research capabilities and industry needs.
In addition, maintaining this expertise within an active research environment could offer an important long-term advantage. Experts working within the existing Centres benefit from close interaction with researchers, research teams and international academic networks in their respective fields, helping them remain connected to emerging technologies and developments. This continuous exposure to the research ecosystem could be particularly valuable in rapidly evolving technology areas and may be more challenging to maintain within a structure focused primarily on industry support.
It is therefore suggested that a coordinated national model leveraging the capabilities of existing Centres be explored as a potentially faster, more cost-effective and scalable approach to achieving the objectives of the Strategy. The establishment of a completely new institutional structure could then be considered where a clearly identified capability gap cannot be effectively addressed through the existing ecosystem.
ΣΧΟΛΙΟ 1
Αρ. Άρθρου και εδαφίου
Παράρτημα Β «AI Use Case Lifecycle and Control Gates», Control Gates 1 έως 4 (σελ. 57–59), σε συνδυασμό με την παράγραφο 3.3.2 «Control Framework», εδάφιο «Approval gates before procurement, deployment, scaling or material modifications» (σελ. 27).
Σχόλιο / Εισήγηση
Να καθοριστούν ρητά, ανά πύλη ελέγχου, το αρμόδιο εγκριτικό όργανο και τα κριτήρια αξιολόγησης. Για συστήματα που δεν χαρακτηρίζονται υψηλού κινδύνου κατά τον Καν. (ΕΕ) 2024/1689, οι εγκρίσεις να διενεργούνται από τον ίδιο τον φορέα υλοποίησης. Όπου απαιτείται κεντρική έγκριση, να τεθεί δεσμευτική προθεσμία απόκρισης, η άπρακτη πάροδος της οποίας να λογίζεται ως έγκριση. Να προβλεφθεί διαδικασία ένστασης σε περίπτωση απόρριψης.
Αιτιολόγηση σχολίου / Εισήγησης
Το κείμενο εισάγει τέσσερα σημεία υποχρεωτικής έγκρισης ανά έργο, χωρίς να προσδιορίζει αρμόδιο όργανο, κριτήρια αξιολόγησης, προθεσμία απόκρισης ή δικαίωμα ένστασης. Οι φορείς δεν μπορούν να προγραμματίσουν χρόνο ή πιστώσεις, με αποτέλεσμα η ρύθμιση να λειτουργεί ως αντικίνητρο υλοποίησης έργων και όχι ως μηχανισμός διασφάλισης ποιότητας. Υφίσταται και εσωτερική αντίφαση εντός της Στρατηγικής: το Κεφάλαιο 5 θέτει προθεσμία οκτώ μηνών για την προκήρυξη των πρώτων έξι μεγάλων έργων και δώδεκα μηνών για τον εντοπισμό πέντε εφαρμογών ανά Υπουργείο, ενώ ταυτόχρονα εισάγονται τέσσερις εγκρίσεις ανοικτού χρόνου. Δεδομένου του ρυθμού εξέλιξης της τεχνολογίας, λύση που εγκρίνεται με σημαντική καθυστέρηση ενδέχεται να έχει καταστεί τεχνολογικά παρωχημένη πριν τεθεί σε λειτουργία. Επισημαίνεται τέλος ότι ο Καν. (ΕΕ) 2024/1689 δεν προβλέπει οποιαδήποτε εκ των προτέρων έγκριση από εθνική αρχή, για τα συστήματα υψηλού κινδύνου του Παραρτήματος III η αξιολόγηση συμμόρφωσης διενεργείται με εσωτερικό έλεγχο του ίδιου του φορέα (Παράρτημα VI του Κανονισμού). Πρόκειται συνεπώς για εθνική προσθήκη, η οποία επιδέχεται προσαρμογή χωρίς κίνδυνο μη συμμόρφωσης με το ενωσιακό δίκαιο.
ΣΧΟΛΙΟ 2
Αρ. Άρθρου και εδαφίου
Παράγραφος 3.5, ενότητα «Government and Public Sector», εδάφια «Common Intelligent Government Platform» και «Adoption Principles – Build Once, Reuse Everywhere» (σελ. 30–31), σε συνδυασμό με Παράρτημα Γ, «Government and Public Sector – Flagship programme(s)» (σελ. 62).
Σχόλιο / Εισήγηση
Η αρχή «Build Once, Reuse Everywhere» και η χρήση της κοινής κυβερνητικής πλατφόρμας να διατυπωθούν ως δυνατότητα και όχι ως υποχρέωση, με ρητή πρόβλεψη εξαίρεσης όπου υφίσταται ήδη λειτουργούσα λύση ή όπου συντρέχουν ειδικές επιχειρησιακές απαιτήσεις τις οποίες η κοινή πλατφόρμα δεν καλύπτει. Η υποχρέωση επαναχρησιμοποίησης να περιοριστεί ρητά στο τεχνικό υπόστρωμα και να μην επεκτείνεται στην επιχειρησιακή λογική των φορέων.
Αιτιολόγηση σχολίου / Εισήγησης
Η κοινή πλατφόρμα περιλαμβάνει ονομαστικά τη διαχείριση υποθέσεων και την επεξεργασία εγγράφων. Οι όροι αυτοί είναι γενικοί, όμως το περιεχόμενό τους διαφέρει ριζικά ανά φορέα. Ενδεικτικά: η επεξεργασία εγγράφων για την αξιολόγηση επιλεξιμότητας σε επίδομα πρόνοιας αφορά τραπεζικές καταστάσεις, ενοικιαστήρια και βεβαιώσεις εισοδήματος, με αντιστοίχιση σε κανόνες που μεταβάλλονται νομοθετικά. Στον τελωνειακό έλεγχο αφορά ανάλυση εικόνων σαρωτή και παραστατικών μεταφοράς σε πραγματικό χρόνο, δηλαδή τεχνολογία υπολογιστικής όρασης. Στον τομέα της υγείας αφορά ιατρικά δεδομένα υπό κλινική ευθύνη, με ενδεχόμενη υπαγωγή σε καθεστώς ιατροτεχνολογικού προϊόντος. Στις νομικές υπηρεσίες αφορά ανάλυση νομοθεσίας και νομολογίας. Το πράγματι επαναχρησιμοποιήσιμο τμήμα περιορίζεται στο τεχνικό υπόστρωμα, ενώ η επιχειρησιακή λογική, η νομική βάση επεξεργασίας, οι περίοδοι τήρησης, τα απαιτούμενα επίπεδα ακρίβειας και η κατάταξη κινδύνου κατά τον Καν. (ΕΕ) 2024/1689 διαφέρουν εξ ολοκλήρου. Επιπροσθέτως, η υποχρεωτική επαναχρησιμοποίηση προϋποθέτει κοινό μοντέλο δεδομένων μεταξύ φορέων, το οποίο δεν υφίσταται, η ίδια η Στρατηγική διαπιστώνει κατακερματισμό υποδομών και ανώριμη διακυβέρνηση δεδομένων. Η διατύπωση της αρχής ως δεσμευτικής, με δηλωμένο σκοπό την εξάλειψη των διπλών προμηθειών, καθιστά την εφαρμογή της πρακτικά ανέφικτη και ενδέχεται να εμποδίσει φορείς από την ανάπτυξη λύσεων προσαρμοσμένων στις πραγματικές τους ανάγκες.
ΣΧΟΛΙΟ 3
Αρ. Άρθρου και εδαφίου
Παράγραφος 3.3.2 «Control Framework», εδάφιο «Use of approved and certified delivery and implementation partners in line with established governance and procurement requirements» (σελ. 27).
Σχόλιο / Εισήγηση
Να απαλειφθεί η πρόνοια ή να μετατραπεί σε μη δεσμευτική σύσταση. Εφόσον διατηρηθεί, να διευκρινιστεί ρητά ότι δεν υποκαθιστά και δεν περιορίζει τη διαδικασία επιλογής αναδόχου κατά τη νομοθεσία περί δημοσίων συμβάσεων, ότι γίνονται δεκτά ισοδύναμα πιστοποιητικά και άλλα αποδεικτικά μέσα, και να προβλεφθεί μεταβατική ρύθμιση για τις ενεργές συμβάσεις.
Αιτιολόγηση σχολίου / Εισήγησης
Η πρόνοια δημιουργεί παράλληλο μηχανισμό προεπιλογής προμηθευτών εκτός της διαδικασίας του διαγωνισμού και εκτιμάται ότι αντίκειται στο ισχύον πλαίσιο δημοσίων συμβάσεων για τέσσερις λόγους. Πρώτον, η καταλληλότητα των οικονομικών φορέων κρίνεται από την αναθέτουσα αρχή ανά διαγωνισμό, με κριτήρια που συνδέονται και είναι ανάλογα προς το συγκεκριμένο αντικείμενο, γενικά συστήματα προεπιλογής προβλέπονται μόνο για τους φορείς κοινής ωφέλειας και όχι για τις κλασικές δημόσιες συμβάσεις. Δεύτερον, όπου επιτρέπεται απαίτηση πιστοποίησης, η αναθέτουσα αρχή υποχρεούται να αποδέχεται ισοδύναμα πιστοποιητικά και άλλα αποδεικτικά μέσα, δυνατότητα την οποία ο κλειστός κατάλογος καταργεί στην πράξη. Τρίτον, η τήρηση του καταλόγου ανατίθεται στην Εθνική Αρχή ΤΝ, η οποία ταυτόχρονα λειτουργεί τον Government AI Accelerator και τις κοινές πλατφόρμες, το ίδιο όργανο δηλαδή που παρέχει λύσεις αποφασίζει ποιοι τρίτοι επιτρέπεται να τις ανταγωνιστούν, γεγονός που εγείρει ζήτημα σύγκρουσης συμφερόντων. Τέταρτον, ο περιορισμός θίγει την πρόσβαση μικρομεσαίων επιχειρήσεων και οικονομικών φορέων άλλων κρατών μελών, με προβλέψιμο αποτέλεσμα τη μείωση των υποβαλλόμενων προσφορών και την αύξηση του κόστους. Σημειώνεται ότι ο Καν. (ΕΕ) 2024/1689 δεν περιέχει καμία πρόβλεψη περί καταλόγων εγκεκριμένων αναδόχων.
ΣΧΟΛΙΟ 4
Αρ. Άρθρου και εδαφίου
Παράγραφος 3.9.6 «AI Social Contract Principles», εδάφιο περί καταχώρισης στη βάση δεδομένων της ΕΕ και ετήσιου ελέγχου από την «Cyprus AI Security & Certification Authority» (σελ. 43). Σε συνδυασμό με: παράγραφο 3.3.1 «Government AI Accelerator» (σελ. 25), παράγραφο 3.5 «Portfolio Governance and Review» (σελ. 31), Παράρτημα Γ «Public Sector» (σελ. 60) και Κεφάλαιο 5, σημεία 4 και 6 (σελ. 51–52).
Σχόλιο / Εισήγηση
Οι υποχρεώσεις καταχώρισης, αναφοράς και ελέγχου να περιοριστούν σε όσα ήδη επιβάλλει ο Καν. (ΕΕ) 2024/1689. Ειδικότερα, να απαλειφθεί η πρόβλεψη ετήσιου ελέγχου σε κάθε οργανισμό «χωρίς εξαίρεση» και να προβλεφθεί ενιαίο σημείο καταχώρισης και υποβολής αναφορών, αντί των τριών παράλληλων μητρώων. Για Υπηρεσίες που υπάγονται σε Υπουργείο ή Υφυπουργείο, η υποβολή να γίνεται μέσω του εποπτεύοντος Υπουργείου και όχι χωριστά ανά Υπηρεσία. Να ενοποιηθεί επίσης η ορολογία και η συχνότητα επικαιροποίησης της στρατηγικής ΤΝ ανά φορέα, η οποία σήμερα αναφέρεται ως τριετής στην παράγραφο 3.3.1 και ως ετήσια στο Παράρτημα Γ.
Αιτιολόγηση σχολίου / Εισήγησης
Σωρευτικά επιβάλλονται: ετήσια δημοσίευση στρατηγικής ΤΝ ανά φορέα με προθεσμία τον Μάρτιο 2027, τριμηνιαίες αναφορές χαρτοφυλακίου, εντοπισμός πέντε νέων εφαρμογών ανά έτος, καταχώριση σε τρία διαφορετικά μητρώα και ετήσιος εξωτερικός έλεγχος σε κάθε οργανισμό χωρίς εξαίρεση. Το άθροισμα συνιστά μόνιμη διοικητική απασχόληση την οποία οι φορείς, με τη σημερινή τους στελέχωση, δεν μπορούν να απορροφήσουν χωρίς να θιγεί το κύριο έργο τους, ενώ σημαντικό μέρος της ζητούμενης πληροφορίας είναι ταυτόσημο και απλώς επαναλαμβάνεται. Από το σύνολο αυτό, ο Καν. (ΕΕ) 2024/1689 απαιτεί μόνο την καταχώριση στη βάση δεδομένων της ΕΕ. Ετήσιος έλεγχος από εθνική αρχή πιστοποίησης δεν προβλέπεται πουθενά στον Κανονισμό, ενώ τα πρότυπα ISO 42001 και ISO 27001 έχουν εθελοντικό χαρακτήρα. Επισημαίνεται περαιτέρω ότι η αναφερόμενη «Cyprus AI Security & Certification Authority» δεν περιλαμβάνεται στο μοντέλο διακυβέρνησης της παραγράφου 3.3.1 ούτε περιγράφεται σε άλλο σημείο του κειμένου, με αποτέλεσμα να ανατίθεται υποχρέωση ετήσιου ελέγχου σε φορέα του οποίου η σύσταση, οι αρμοδιότητες και η διαδικασία δεν έχουν καθοριστεί.
ΣΧΟΛΙΟ 5
Αρ. Άρθρου και εδαφίου
Παράρτημα Β «AI Use Case Lifecycle and Control Gates», Control Gate 1 και Control Gate 2 (σελ. 57–58).
Σχόλιο / Εισήγηση
Να προστεθεί ρητή μεταβατική διάταξη ώστε έργα τεχνητής νοημοσύνης που έχουν ήδη ανατεθεί και βρίσκονται σε στάδιο υλοποίησης να συνεχίζονται κανονικά και να εντάσσονται στο πλαίσιο από το επόμενο σημείο ελέγχου και εφεξής, χωρίς αναδρομική εφαρμογή εγκρίσεων. Σε κάθε περίπτωση, οι εθνικές προθεσμίες συμμόρφωσης δεν πρέπει να είναι συντομότερες από τις μεταβατικές προθεσμίες που ορίζει το άρθρο 111 του Καν. (ΕΕ) 2024/1689 για τους δημόσιους φορείς.
Αιτιολόγηση σχολίου / Εισήγησης
Τα σημεία έγκρισης τοποθετούνται πριν την προμήθεια και πριν την ανάπτυξη, χωρίς καμία αναφορά σε έργα που βρίσκονται ήδη σε εξέλιξη κατά την έναρξη ισχύος του πλαισίου. Χωρίς μεταβατική ρύθμιση, ενεργές συμβάσεις ενδέχεται να κληθούν να περάσουν αναδρομικά από εγκρίσεις που δεν υφίσταντο κατά τον χρόνο της ανάθεσης, με κίνδυνο αναστολής συμβατικών χρονοδιαγραμμάτων και δημοσιονομικών δεσμεύσεων. Επισημαίνεται ότι ο ενωσιακός νομοθέτης έχει ήδη αναγνωρίσει την ανάγκη μεταβατικής περιόδου για τον δημόσιο τομέα, ορίζοντας στο άρθρο 111 του Κανονισμού προθεσμία συμμόρφωσης για συστήματα υψηλού κινδύνου που προορίζονται για χρήση από δημόσιες αρχές. Εθνικό κείμενο πολιτικής δεν θα πρέπει να θέτει αυστηρότερα χρονικά όρια από την υπερκείμενη ενωσιακή ρύθμιση.
ΣΧΟΛΙΟ 6
Στο άρθρο 3.3.1.7 αναφέρεται ότι “every ministry deploying AI will be required to maintain its own Applied AI Strategy aligned with the National AI Strategy and in line with the EU AI Act, with an updated adoption plan every 3 years’’
Στο Annex C αναφέρεται ότι “All ministries and public bodies will publish their Institutional AI Strategies by March 2027 and update them annually”.
Σχόλιο / Εισήγηση Στο άρθρο 3.3.1.7 αναφέρεται σε κάθε Υπουργείο καθώς και στην υποχρέωση ανανέωσης της Στρατηγικής του κάθε 3 χρόνια ενώ στο Annex C αναφέρεται και σε δημόσια σώματα πέραν απο τα Υπουργεία αναφέροντας υποχρέωση ετήσιας ανανέωσης της Στρατηγικής .
Αιτιολόγηση σχολίου / Εισήγησης Το ερώτημα είναι η υποχρέωση διατήρησης Στρατηγικής ΤΝ εκτείνετεται πέραν απο τα Υπουργεία και σε Υφυπουργεία; Επίσης η εν λόγω στρατηγική θα πρέπει να ανανεώνεται κάθε 3 χρόνια ή ετησίως; To ερώτημα υποβάλλεται για λόγους διασαφήνισης της υποχρέωσης και ομοιομορφίας του χρονικού πλαισίου.
ΣΧΟΛΙΟ 7
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο –
Το άρθρο 1 αναφέρει “The development of the National AI Strategy considers elements that act as the ethical and operational guardrails for all AI activities in Cyprus»
Σχόλιο / Εισήγηση Είναι χρήσιμο να δοθεί πιο εξειδικευμένη ερμηνεία του «AI activities in Cyprus» και να καθοριστεί το πεδίο εφαρμογής της εν λόγω Στρατηγικής (για ποιά ακριβώς εργαλεία ΤΝ θα εφαρμόζεται).
Αιτιολόγηση σχολίου / Εισήγησης Με τον τρόπο αυτό θα γίνει πιο κατανοητό το εύρος εφαρμογής της Στρατηγικής κατά την εκτέλεση επαγγελματικών δραστηριοτήτων.
Associate Scientist at the Cyprus Institute of Neurology and Genetics; Member of the Cyprus Review Bioethics Committee for Biomedical Research and Clinical Trials on Medicinal Products of Human Use A’.
The comments below refer to Section 2 and are relevant to the main objectives and priorities of the National AI strategy.
1. 2.4.: I suggest two additions to the five key ideas, specifically:
a) Continuously monitored AI: ensure ongoing evaluation of its socio-economic and environmental impact based on real-time data and allow for interventions where necessary to optimise cost-benefit balance.
b) AI strictly regulated by law: prioritize the establishment of a detailed legal framework for AI regulation across all sectors, prior to nation-wide implementation.
The above key ideas should also be reflected in the description of the Priorities and Objectives:
2. 2.4.1: Healthcare and Life Sciences: regulate legal accountability for medical decisions assisted by AI.
Education and Human Capital Development: establish a legal age limit for using AI within primary and secondary education. Institutions should have a clear regulation code regarding the acceptable applications of AI by students and teaching personnel. Monitoring systems should be in place to assess educational outcomes. This will ensure that essential brain development in young children will not be hindered by excessive reliance on AI and that students will have the opportunity to acquire basic critical thinking and research skills before employing AI-assisted learning.
Add Agriculture as a priority sector for AI: agriculture in Cyprus has a great potential of becoming one of the major economy drivers and build the foundation for a less tourist-dependant economy with higher resilience to geopolitical turbulence. It is also one of the areas where the impact of AI can be substantial, especially where automation and optimisation are required e.g. for crops management and processing of produce.
3. 2.5: Add a separate Objective addressing legal regulation (see comment 1b above), including all relevant sectors. In addition to healthcare and education, issues such as patents, copyright and plagiarism should be examined considering AI application in innovative product development, arts and content creation.
4. 2.5.5. objective 5: A clear plan should be conducted on the allocation of the 3000 AI professionals, starting with a pilot study examining the effect of such a development on the overall workforce of Cyprus. Among other issues, this study should focus on measures to prevent staff shortages in other critical priority sectors and on possible socio-economic effects.
ΕΙΣΗΓΗΣΕΙΣ ΓΕΝΙΚΟΥ ΧΗΜΕΙΟΥ ΤΟΥ ΚΡΑΤΟΥΣ (ΓΧΚ):
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 1
Article / paragraph
Section 2.4.1 – Priority Sectors for Leadership: Healthcare and Life Sciences
Annex C – Healthcare and Life Sciences
Comment / Recommendation
The Healthcare and Life Sciences pillar should explicitly recognize the role of Public Health Laboratories and laboratory intelligence as an integral component of AI-enabled healthcare and public health.
The Strategy should include:
“AI-supported laboratory analytics for food safety, environmental monitoring, toxicology and chemical risk assessment.”
Justification
The Strategy appropriately identifies Healthcare and Life Sciences as a priority sector and focuses on clinical decision-making, preventive care, health data and healthcare system optimization. However, the laboratory dimension of public health is not sufficiently reflected.
The SGL is a key national scientific and laboratory institution supporting public health through laboratory surveillance and analytical activities in areas including food safety, environmental health, drinking water quality, chemical hazards and toxicology.
AI-supported laboratory analytics could enhance the interpretation of complex analytical datasets, support early identification of emerging hazards and strengthen evidence-based public health decision-making.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 2
Article / paragraph
Section 3.2.1 – Strategic Role of Data
Section 3.2.3 – Interoperability and Secure Data Sharing
Comment / Recommendation
The proposed federated national data architecture should explicitly recognize a:
National Laboratory Data Space
This should enable secure and governed interoperability between the State General Laboratory, hospitals, Veterinary Services, environmental authorities, water authorities, universities and other relevant public-sector and research institutions.
Justification
The Strategy correctly recognizes data as a strategic national asset and proposes secure interoperability across ministries, hospitals, universities and regulated sectors. It also identifies health and environment among the potential sectoral data spaces.
A dedicated National Laboratory Data Space would complement this architecture by bringing together high-value scientific and analytical laboratory data relevant to public health, food safety, environmental health, chemical safety and toxicology.
Such an approach would support secure data sharing, research and innovation, early warning, risk assessment and evidence-based decision-making, while preserving appropriate access controls, data protection and auditability.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 3
Article / paragraph
Section 3.4 – AI Adoption Across Government
Section 3.4.1 – Priority Areas for Government Adoption
Section 3.4.2 – Use Case Driven Approach
Comment / Recommendation
The Strategy should explicitly include public health laboratory intelligence and national chemical intelligence among the high-value government AI use cases.
AI applications should support:
• analysis of large-scale laboratory datasets;
• detection of emerging trends and anomalies;
• identification and forecasting of chemical and biological hazards;
• early warning and surveillance;
• population exposure assessment;
• evidence-based decision-making.
Justification
The Strategy promotes practical, high-value AI use cases in government, including analytical and forecasting capabilities for evidence-based decision-making.
The State General Laboratory generates and interprets large volumes of scientific laboratory data. These data represent an important national asset for public health protection and can provide valuable signals for emerging risks.
Explicitly recognizing laboratory intelligence and national chemical intelligence would extend the Strategy beyond administrative and clinical applications and strengthen its public health and prevention dimension.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 4
Article / paragraph
Section 3.5 – Priority Sectors
Section 3.8 – Research, Innovation and Ecosystem Development
Annex D – Research and Innovation, Focus Area 1: Energy, Environment and Resource Management; Focus Area 3: Healthcare
Comment / Recommendation
The Strategy should adopt a One Health perspective in the development and application of AI for health, environmental and food-safety surveillance.
The Strategy should include:
“AI should support One Health surveillance through the integrated analysis of laboratory, environmental and food safety data.”
Justification
The Strategy already identifies Healthcare, Environment and Resource Management as important areas for AI research and highlights the importance of integrated, evidence-based approaches.
The One Health approach provides an appropriate framework for connecting human health, animal health, food safety and environmental health.
The State General Laboratory contributes through the generation and interpretation of laboratory data across several of these domains. Integrating relevant datasets through AI could improve early detection of emerging hazards and strengthen national preparedness and prevention.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 5
Article / paragraph
Section 3.13 – Risk Management, Resilience and Adaptation
Section 3.4.2 – Use Case Driven Approach
Comment / Recommendation
The Strategy should explicitly recognize the use of AI in risk assessment and early warning for chemical and public health hazards, including:
• intelligent sample prioritization;
• anomaly detection;
• contamination prediction;
• exposure modelling;
• horizon scanning.
Justification
The Strategy already identifies risk identification and assessment, including ongoing horizon scanning, as an important component of national AI resilience.
AI can significantly strengthen scientific risk assessment by identifying patterns and emerging signals across large and heterogeneous datasets.
For the State General Laboratory, such applications could support the prioritization of laboratory resources, improve early identification of emerging hazards and strengthen national preparedness for chemical, food and environmental risks.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 6
Article / paragraph
Section 3.4.4 – Shared Capabilities and Reuse
Section 3.2.3 – Interoperability and Secure Data Sharing
Section 3.7 – Infrastructure, Compute and Digital Sovereignty
Comment / Recommendation
The Strategy should explicitly recognize AI-enabled digital laboratory infrastructure as a component of public-sector AI transformation.
This should include:
• Laboratory Information Management Systems (LIMS);
• digital laboratories;
• intelligent laboratory workflows;
• AI-enabled analytical and decision-support tools.
Justification
The Strategy promotes shared platforms, reusable components, interoperability and common capabilities across government.
Laboratory systems constitute a specialized but strategically important component of public-sector digital infrastructure. AI-enabled LIMS and intelligent laboratory workflows could improve laboratory efficiency, data quality, traceability, resource allocation and decision support.
This would also create a practical pathway for connecting laboratory data with wider national health, environmental and food-safety data infrastructures.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 7
Article / paragraph
Section 3.1.2 – Design Principles
Section 3.4.3 – Human Oversight and Accountability
Section 3.9.3 – Transparency and Explainability
Comment / Recommendation
The Strategy should explicitly require Explainable AI principles for AI systems supporting laboratory analysis, chemical risk assessment and public health surveillance.
The Strategy should emphasize:
transparency, auditability, scientific traceability and mandatory human oversight for high-impact decisions.
Justification
The Strategy already establishes explainability, auditability, human oversight and accountability as fundamental principles of responsible AI.
These principles are particularly important in laboratory and scientific applications because analytical results generated by the State General Laboratory may support regulatory, public health, customs, law-enforcement and judicial processes.
For such applications, it is essential that AI-supported outputs can be scientifically interpreted, traced and audited, while final high-impact decisions remain subject to appropriate expert human oversight.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 8 – Proposed Pilot Applications
Article / paragraph
Section 3.4.2 – Use Case Driven Approach
Annex C – Priority Sectors for Leadership
Annex D – Research and Innovation
Comment / Recommendation
The State General Laboratory proposes the consideration of the following pilot AI applications in the field of public health laboratory science:
1. Intelligent Food Safety Surveillance
2. AI-supported Drinking Water Quality Monitoring
3. AI-supported Environmental Surveillance and Early Hazard Detection
4. Intelligent Laboratory Sample Prioritization
5. AI-assisted Chemical Risk Assessment
6. Smart Laboratory Information Management Systems (Smart LIMS)
7. National Early Warning System for Chemical Hazards
8. AI-enabled Scientific Assistant for State General Laboratory scientists
9. AI-supported Public Health Crisis Management
10. National AI Platform for Public Health Chemistry
11. AI and Chemoinformatic for the Automated Assessment and Classification of New Psychoactive Substances (NPS)
Justification
The Strategy explicitly promotes a use-case-driven approach, prioritizing applications that demonstrate measurable public value, feasibility, data readiness and manageable risk.
The proposed applications provide concrete examples of how this approach could be implemented within public health laboratory services.
They build on SGL’s existing scientific expertise, laboratory infrastructure and analytical data and could provide suitable pilot projects for the responsible application of AI in food safety, environmental health, toxicology, chemical safety and public health surveillance.
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 9 – SGL readiness and contribution
Article / paragraph
Section 3.8 – Research, Innovation and Ecosystem Development
Section 3.4 – AI Adoption Across Government
Objective 8 – Develop Sovereign Capability through Partnerships
Comment / Recommendation
The State General Laboratory considers the application of AI to public health, through the processing and utilization of scientific laboratory data for prevention, surveillance and risk assessment, to be an area of high strategic importance.
The SGL is ready to contribute, in collaboration with other competent authorities and relevant academic and research institutions, to the further development of relevant AI applications and pilot projects in support of the implementation of the National AI Strategy.
Justification
The Strategy emphasizes applied, impact-oriented research, collaboration between government, academia and industry, and the development of sovereign national capabilities through trusted partnerships.
The SGL can contribute specialized scientific expertise, laboratory infrastructure, analytical data and domain knowledge in areas directly relevant to public health, food safety, environmental health, chemical risk and toxicology.
Its participation would therefore support the Strategy’s objectives on public-sector AI adoption, applied research, national capability development and responsible AI deployment.
1. National AI Skills Observatory
Αφορά τις σελίδες 24, 36–37 και 78–79 της Στρατηγικής . Να καθοριστούν ο θεσμικός και λειτουργικός ρόλος της ΑνΑΔ στο National AI Skills Observatory (NASO), οι ευθύνες των συνεργαζόμενων φορέων και ο τρόπος αξιοποίησης των αποτελεσμάτων του στον σχεδιασμό πολιτικών και δράσεων κατάρτισης. Να εξειδικευτεί ο μηχανισμός μέσω του οποίου το NASO θα παρακολουθεί τις επιπτώσεις της ΤΝ στα επαγγέλματα, στα εργασιακά καθήκοντα και στις ανάγκες σε δεξιότητες, περιλαμβανομένων της μεθοδολογίας, των βασικών δεικτών, των πηγών δεδομένων και της συχνότητας παρακολούθησης. Να αξιοποιηθούν οι υφιστάμενοι μηχανισμοί των συνεργαζόμενων Φορέων, αποφεύγοντας επικαλύψεις. Η συνεισφορά της ΑνΑΔ να καθοριστεί με βάση τα δεδομένα και τις αναλύσεις που είναι διαθέσιμα στο πλαίσιο των αρμοδιοτήτων της.
2. Παροχή δεδομένων στο NASO
Αφορά τις σελίδες 20-21 και 79 της Στρατηγικής. Να καθοριστούν τα δεδομένα που θα απαιτείται να παρέχει η ΑνΑΔ στο NASO, η συχνότητα και η μορφή παροχής τους, τα κοινά πρότυπα ανταλλαγής και οι ευθύνες για την ποιότητα και επικαιροποίησή τους. Να διευκρινιστούν η νόμιμη βάση επεξεργασίας, οι απαιτήσεις ασφάλειας και οι τεχνικές προδιαγραφές διασύνδεσης, καθώς και ο τρόπος αντιμετώπισης περιπτώσεων όπου υφιστάμενα πληροφοριακά συστήματα δεν είναι άμεσα συμβατά. Οι συγκεκριμένες κατηγορίες δεδομένων να καθοριστούν σε συνεργασία με τους εμπλεκόμενους φορείς, με βάση τον σκοπό του NASO, την αναγκαιότητα των δεδομένων και τις υφιστάμενες δυνατότητες των πληροφοριακών συστημάτων. Να προβλεφθούν οι αναγκαίοι πόροι για τυχόν απαιτούμενες προσαρμογές. Να καθοριστούν επίσης σαφείς ευθύνες για την παροχή, επικύρωση, επικαιροποίηση και διόρθωση των δεδομένων, καθώς και για τον υπολογισμό και τη δημοσίευση των σχετικών δεικτών.
3. . Διακυβέρνηση του FutureAI CY
Αφορά τις σελίδες 79-80 και 93-94 της Στρατηγικής. Να διευκρινιστεί τι συνεπάγεται για την ΑνΑΔ η συμπροεδρία της AI Upskilling Certification and Quality Committee και να προσδιοριστούν οι αρμοδιότητες της ΑνΑΔ στον σχεδιασμό, στην υλοποίηση, στη διασφάλιση ποιότητας και στην παρακολούθηση του FutureAI CY. Να αποσαφηνιστεί ο μηχανισμός επιλογής, έγκρισης και υλοποίησης των προγραμμάτων κατάρτισης στα οποία θα συμμετέχουν οι δικαιούχοι του FutureAI CY και κατά πόσο θα αξιοποιηθούν υφιστάμενα Σχέδια και διαδικασίες της ΑνΑΔ ή θα εφαρμοστεί διαφορετικός μηχανισμός. Να αποσαφηνιστεί επίσης η σχέση με το Σύστημα Αξιολόγησης και Πιστοποίησης Συντελεστών Παροχής Κατάρτισης, το Συστημα Επαγγελματικών Προσόντων και τις αρμοδιότητες άλλων αρμόδιων φορέων, περιλαμβανομένου του ΔΙΠΑΕ, ώστε να αποφεύγονται παράλληλες διαδικασίες και επικαλύψεις. Στη διακυβέρνηση του FutureAI CY να εξεταστεί η συμμετοχή του Υπουργείου Εργασίας και Κοινωνικών Ασφαλίσεων και αντιπροσωπευτικών οργανώσεων εργοδοτών και εργαζομένων, καθώς και άλλων σχετικών φορέων, με σαφή καθορισμό του ρόλου τους. Επιπρόσθετα, να διευκρινιστεί ο τρόπος λειτουργίας και λήψης αποφάσεων της Επιτροπής.
4. Πιστοποίηση παρόχων και μητρώο διαπιστευτηρίων
Αφορά τις σελίδες 79-80 και 93-94 της Στρατηγικής. Να διευκρινιστεί το αντικείμενο των όρων provider accreditation και credentials registry που χρησιμοποιούνται στη Στρατηγική, περιλαμβανομένων των κατηγοριών παρόχων και διαπιστευτηρίων που καλύπτονται. Να καθοριστούν ο αρμόδιος φορέας, τα κριτήρια και οι διαδικασίες για έγκριση, εγγραφή, ανανέωση, αναστολή ή ανάκληση, καθώς και οι διαδικασίες επανεξέτασης ή ένστασης όπου απαιτούνται. Να καθοριστεί, όπου είναι αναγκαίο, ο τρόπος αναγνώρισης ή αντιστοίχισης υφιστάμενων εθνικών και διεθνών πιστοποιήσεων και η σχέση τους με τα σχετικά εθνικά και ευρωπαϊκά πλαίσια προσόντων. Να εξεταστεί κατά προτεραιότητα η αξιοποίηση ή επέκταση υφιστάμενων συστημάτων πιστοποίησης (Σύστημα Αξιολόγησης και Πιστοποίησης Συντελεστών Παροχής Κατάρτισης, το Συστημα Επαγγελματικών Προσόντων) και μητρώων της ΑνΑΔ, όπου αυτά μπορούν να καλύψουν τις νέες απαιτήσεις, αντί της δημιουργίας παράλληλων διαδικασιών και συστημάτων. Να αποσαφηνιστεί επίσης αν το credentials registry θα υλοποιηθεί ως κεντρική εθνική υπηρεσία ή μέσω διασύνδεσης με υφιστάμενα μητρώα και πληροφοριακά συστήματα, καθώς και οι ευθύνες λειτουργίας, ενημέρωσης, τεχνικής υποστήριξης και χρηματοδότησής του.
5. Μικροδιαπιστευτήρια 5–15 ECTS
Αφορά τις σελίδες 80-81 της Στρατηγικής . Η Στρατηγική προβλέπει μικροδιαπιστευτήρια 5–15 ECTS, χωρίς να αποσαφηνίζει πλήρως ποιοι φορείς θα τα απονέμουν, πώς θα αναγνωρίζονται και πώς θα συνδέονται με τους μηχανισμούς χρηματοδότησης και πιστοποίησης της κατάρτισης. Η διευκρίνιση είναι αναγκαία, ώστε να διαχωριστούν σαφώς οι ακαδημαϊκές λειτουργίες από τις λειτουργίες χρηματοδότησης και πιστοποίησης της κατάρτισης, δεδομένου ότι δεν εμπίπτουν όλες στις αρμοδιότητες της ΑνΑΔ, όπως, για παράδειγμα, τα ECTS. Υποβάλλεται επίσης εισήγηση να εξεταστεί η συμπερίληψη αναφοράς στο ECVET, το οποίο σχετίζεται με δραστηριότητες της ΑνΑΔ. Η συγκεκριμένη εισήγηση προϋποθέτει την έγκριση του Διοικητικού Συμβουλίου της ΑνΑΔ.
6. Χρηματοδότηση και σύστημα κουπονιών του FutureAI CY
Αφορά τις σελίδες 80-81 της Στρατηγικής. Να αποσαφηνιστεί ο μηχανισμός χρηματοδότησης και υλοποίησης του FutureAI CY, περιλαμβανομένου του κατά πόσο θα εφαρμοστεί το προτεινόμενο local voucher scheme ή άλλη κατάλληλη διευθέτηση. Σε περίπτωση εφαρμογής συστήματος κουπονιών, να καθοριστούν οι πηγές χρηματοδότησης ανά κατηγορία δικαιούχου, καθώς και οι φορείς έγκρισης, διαχείρισης, εξαργύρωσης και ελέγχου. Να διευκρινιστεί επίσης αν η τεχνική διαχείριση του συστήματος κουπονιών θα πραγματοποιείται μέσω κεντρικής εθνικής πλατφόρμας ή μέσω διασύνδεσης με υφιστάμενα συστήματα και να καθοριστούν οι σχετικές ευθύνες λειτουργίας, τεχνικής υποστήριξης και χρηματοδότησης. Πρόσθετα να διευκρινιστεί η σχέση του μηχανισμού με τα υφιστάμενα Σχέδια της ΑνΑΔ και η δυνατότητα χρηματοδότησης από άλλες εθνικές ή ευρωπαϊκές πηγές, όπου απαιτείται. Σημειώνεται ότι, η ΑνΑΔ δεν νομιμοποιείται να χρηματοδοτήσει μέσω του συστήματος κουπονιών (voucher scheme) κατηγορίες δικαιούχων για τους οποίους δεν καταβάλλεται Τέλος Ανάπτυξης Ανθρώπινου Δυναμικού, όπως εργοδοτούμενους στον δημόσιο τομέα (public sector officials/servants) και τους συνταξιούχους. Η χρηματοδότηση των ομάδων αυτών θα πρέπει να καλυφθεί από άλλους εθνικούς πόρους ή ευρωπαϊκά κονδύλια.Προτείνεται η ρητή αποσαφήνιση των πηγών χρηματοδότησης ανά κατηγορία δικαιούχου στο κείμενο της Στρατηγικής.
7. Ομάδες στόχου και επιλέξιμοι δικαιούχοι
Αφορά τη σελίδα 80 της Στρατηγικής. Να προσδιοριστούν χωριστά οι ομάδες στόχου του εθνικού προγράμματος FutureAI CY και οι κατηγορίες συμμετεχόντων των οποίων η κατάρτιση δύναται να χρηματοδοτείται από την ΑνΑΔ σύμφωνα με το εφαρμοστέο θεσμικό πλαίσιο και τα σχετικά Σχέδιά της. Για κατηγορίες συμμετεχόντων που δεν χρηματοδοτούνται από την ΑνΑΔ να προσδιοριστούν άλλες κατάλληλες εθνικές ή ευρωπαϊκές πηγές χρηματοδότησης. Η ύπαρξη διαφορετικής πηγής χρηματοδότησης δεν θα πρέπει από μόνη της να συνεπάγεται αποκλεισμό μιας ομάδας από το εθνικό πρόγραμμα.
8. Δείκτες απόδοσης και αξιολόγηση αποτελεσμάτων
Αφορά τις σελίδες 44-45, 80-81 και 93-94 της Στρατηγικής. Για κάθε βασικό δείκτη απόδοσης (KPI) που θα υιοθετηθεί στο πλαίσιο εφαρμογής της Στρατηγικής να καθορίζονται ποσοτικοποιημένος στόχος, σημείο αναφοράς όπου απαιτείται, πηγή δεδομένων, υπεύθυνος φορέας, συχνότητα μέτρησης και μεθοδολογία υπολογισμού. Για το FutureAI CY να καθοριστούν δείκτες που να επιτρέπουν την αξιολόγηση της επίδρασης της κατάρτισης στην ανάπτυξη δεξιοτήτων, στην παραγωγικότητα, στην απασχολησιμότητα ή απασχόληση και, όπου είναι κατάλληλο, σε άλλα μετρήσιμα εργασιακά αποτελέσματα. Οι δείκτες αυτοί να συνδέονται με την ανεξάρτητη αξιολόγηση της πιλοτικής εφαρμογής πριν από την ευρύτερη ανάπτυξη του προγράμματος.
9. Εφαρμογή των προβλέψεων της Στρατηγικής στην ΑνΑΔ
Αφορά τις σελίδες 24-25 της Στρατηγικής. Να διευκρινιστεί αν και σε ποιο βαθμό οι προβλέψεις για public bodies/public sector organisations εφαρμόζονται στην ΑνΑΔ ως νομικό πρόσωπο δημοσίου δικαίου. Να προσδιοριστούν οι υποχρεώσεις διακυβέρνησης, ελέγχων, αξιολόγησης κινδύνων, αναφορών, ανταλλαγής δεδομένων και κατάρτισης, με σαφή κατανομή ευθυνών και απαιτούμενων πόρων.
10. Institutional AI Strategy της ΑνΑΔ
Αφορά τις σελίδες 25, 60-61 της Στρατηγικής. Να αποσαφηνιστεί αν η ΑνΑΔ υπάγεται στην υποχρέωση εκπόνησης και δημοσίευσης Institutional AI Strategy. Εφόσον υπάγεται, να καθοριστούν το ελάχιστο περιεχόμενο, η διαδικασία εκπόνησης και έγκρισης, η αρμόδια αρχή, το χρονοδιάγραμμα και η σχέση της στρατηγικής με τον υφιστάμενο στρατηγικό σχεδιασμό και την εταιρική διακυβέρνηση της ΑνΑΔ. Να αποσαφηνιστεί επίσης η διάκριση και η σχέση μεταξύ Institutional AI Strategy, Applied AI Strategy και AI adoption plan, καθώς και η προβλεπόμενη συχνότητα επικαιροποίησης κάθε εγγράφου, δεδομένων των διαφορετικών σχετικών αναφορών στη Στρατηγική.
11. AI Champion και AI Officer
Στη σελίδα 22 της Στρατηγικής προβλέπεται ο διορισμός AI Champions από κάθε υπουργείο, ενώ στις σελίδες 26–27 και 91–92 προβλέπεται ο ορισμός AI Officers σε υπουργεία και καθορισμένους οργανισμούς του δημόσιου τομέα. Να επιβεβαιωθεί ότι δεν χρειάζεται ο ορισμός AI Champion από την ΑνΑΔ. Να αποσαφηνιστεί η διαδικασία ορισμού ή παροχής του AI Officer, και να διευκρινιστεί ο ρόλος και η γραμμή αναφοράς των εμπλεκομένων μερών.
12. Συμμετοχή της ΑνΑΔ σε όργανο δεοντολογίας της ΤΝ
Αφορά τις σελίδες 22, 24 και 56 της Στρατηγικής. Να αποσαφηνιστεί αν το National Ethics and Values Committee και το council focused on AI ethics στο οποίο προβλέπεται συμμετοχή της ΑνΑΔ αφορούν στο ίδιο όργανο. Σε περίπτωση διαφορετικών οργάνων, να προσδιοριστούν με συνέπεια η ονομασία, η σύνθεση, οι αρμοδιότητες, οι γραμμές αναφοράς και η μεταξύ τους σχέση. Να διευκρινιστεί επίσης ο συγκεκριμένος ρόλος, οι υποχρεώσεις και ο τρόπος εκπροσώπησης της ΑνΑΔ σε οποιοδήποτε από τα όργανα αυτά προβλέπεται να συμμετέχει. Η ΑνΑΔ σημειώνεται ως Human Resources Development Authority. Παρακαλώ να τροποποιηθεί σε Human Resource Development Authority of Cyprus.
13. Εθνική υποδομή ΤΝ και υφιστάμενα συστήματα της ΑνΑΔ
Αφορά τις σελίδες 38-39, και 61-62 της Στρατηγικής. Να αποσαφηνιστεί το πεδίο εφαρμογής της προβλεπόμενης εθνικής υποδομής ΤΝ και των κοινών υπηρεσιών φιλοξενίας για δημόσιους οργανισμούς που διαθέτουν υφιστάμενες υποδομές και κρίσιμα πληροφοριακά συστήματα. Να καθοριστούν τα κριτήρια βάσει των οποίων μια υπηρεσία θα εντάσσεται σε κεντρική υποδομή ή θα μπορεί να διατηρείται σε υφιστάμενο περιβάλλον, λαμβάνοντας υπόψη την ασφάλεια, την επιχειρησιακή συνέχεια, την τεχνική συμβατότητα, το κόστος και τις κανονιστικές απαιτήσεις. Για τυχόν μετάβαση να καθοριστούν το χρονοδιάγραμμα, η χρηματοδότηση και οι ευθύνες λειτουργίας, αντιγράφων ασφαλείας, ανάκαμψης, ενημερώσεων, παρακολούθησης και αντιμετώπισης περιστατικών. Να μην θεωρείται δεδομένη η μεταφορά υφιστάμενων συστημάτων χωρίς προηγούμενη τεχνική και οικονομική αξιολόγηση.
ΕΙΣΗΓΗΣΕΙΣ ΓΕΝΙΚΟΥ ΧΗΜΕΙΟΥ ΤΟΥ ΚΡΑΤΟΥΣ (ΓΧΚ):
PROPOSED COMMENTS BY THE STATE GENERAL LABORATORY (SGL)
COMMENT 1
Article / paragraph
Section 2.4.1 – Priority Sectors for Leadership: Healthcare and Life Sciences
Annex C – Healthcare and Life Sciences
Comment / Recommendation
The Healthcare and Life Sciences pillar should explicitly recognize the role of Public Health Laboratories and laboratory intelligence as an integral component of AI-enabled healthcare and public health.
The Strategy should include:
“AI-supported laboratory analytics for food safety, environmental monitoring, toxicology and chemical risk assessment.”
Justification
The Strategy appropriately identifies Healthcare and Life Sciences as a priority sector and focuses on clinical decision-making, preventive care, health data and healthcare system optimization. However, the laboratory dimension of public health is not sufficiently reflected.
The SGL is a key national scientific and laboratory institution supporting public health through laboratory surveillance and analytical activities in areas including food safety, environmental health, drinking water quality, chemical hazards and toxicology.
AI-supported laboratory analytics could enhance the interpretation of complex analytical datasets, support early identification of emerging hazards and strengthen evidence-based public health decision-making.
INTRODUCTION
The Cyprus Computer Society (CCS) welcomes the publication of the National AI Strategy 2032 and considers it an important and necessary step for Cyprus to move forward in a coordinated and responsible way in the field of Artificial Intelligence. A clear national strategy is essential for creating a common direction, supporting investment and innovation, strengthening public-sector capabilities, and ensuring that AI developments deliver meaningful benefits for the economy and society.
Recognising the strategic importance of Artificial Intelligence for Cyprus, and with full respect for the extensive work undertaken by the competent authorities, and in response to the call for public consultation, we are pleased to contribute the following comments and suggestions, with the aim of further supporting the implementation as well as the practical delivery of the Strategy.
The comments below are offered in a constructive spirit and acknowledge that, in most cases, the National AI Strategy already includes the relevant principle or refers to the issue concerned. The National AI Strategy already sets out governance structures, control gates, data governance, infrastructure planning, skills development and measurement arrangements at a strategic level. Therefore, they should be viewed as suggestions for further consideration, rather than observations that these subjects are absent.
The purpose of the comments is more specific: to consider how the National AI Strategy can support and ensure effective implementation of the principles it sets out. Hence, rather than proposing new directions or changes to the National AI Strategy’s priorities, our comments focus on the operational detail that can determine whether a strategy is effectively delivered. This is particularly important for AI initiatives, which depend on sustained funding, good data, capable public organisations and effective management of external suppliers. A project may be legally compliant and technically sound, yet still be delayed, exceed its budget or fail to deliver the expected benefits. The comments therefore address areas such as project-delivery assurance, requirements and user acceptance, change control, lifecycle costs, benefits realisation and the organisational capability required to act as effective owners of AI initiatives. The comments are therefore intended as practical refinements to strengthen implementation and help ensure that the National AI Strategy’s principles lead to tangible results for citizens, public administration and the wider economy.
STRATEGIC PERSPECTIVE
The Cyprus National AI Strategy 2032 provides a strong and ambitious foundation for positioning Cyprus as a trusted and competitive participant in the European AI ecosystem.
Its breadth, focus on sovereignty and infrastructure, commitment to responsible AI and alignment with European requirements provide a solid basis for implementation.
To maximise its impact, the Strategy could benefit from clear prioritisation and a focused implementation approach, reflecting Cyprus’s particular strengths, capabilities and opportunities.
A compelling strategic positioning could be: “Cyprus: Europe’s trusted AI gateway to the Eastern Mediterranean.”
This could be supported by focusing on
• AI deployment,
• AI assurance,
• regulated experimentation,
• sectoral AI,
• European market access and
• regional connectivity,
while at the same time leveraging European partnerships and infrastructure.
The success of the Strategy should ultimately be reflected not only in initiatives established by 2032, but in
• measurable productivity gains,
• better public services,
• a stronger AI workforce,
• successful AI companies,
• increased AI exports,
• recognised research and
• trusted AI deployment.
In short: Cyprus has an opportunity to build on a strong AI strategy by sharpening its priorities and focusing implementation where the country can create the greatest value.
Comments and Suggestions
1. Multi-year and sustainable funding
The National AI Strategy could give more detail on the financial arrangements needed to support its implementation over the longer term. In particular, it would be useful to have clearer information on how funding for major initiatives will continue after the initial implementation phase and how this funding will be linked to agreed priorities and delivery milestones.
Reference in Strategy: §1.4.9 Sustainability and Economic Model, p.6, where the Strategy refers to “Multi-year investment with clear ROI tracking”; and §3.10.3 Funding and Renewal Model, p.44, which refers to a multi-year renewal cycle and predictable capacity.
2. Project-level milestones and completion criteria
In addition to the high-level implementation periods set out in the National AI Strategy, consideration could be given to having more detailed implementation plans for important initiatives. These could include key milestones, expected deliverables, dependencies and target completion dates, together with clear and measurable criteria for deciding whether each stage of a project has been successfully completed.
Reference in Strategy: §1.5 Implementation Timeline and Success Metrics, p.6, which sets out the general 0–8 month, 6–12 month, 12–24 month and 2026–2032 periods. Also §3.3.2 Control Framework, p.27, which establishes approval gates throughout the lifecycle.
3. Reporting, coordination, escalation and corrective action
The National AI Strategy could further specify the operational mechanism through which progress reporting, cross-government coordination and accountability will function in practice, particularly for significant or cross-government initiatives. This could include defined reporting responsibilities, reporting frequency, escalation thresholds, procedures for resolving implementation bottlenecks, and the circumstances under which corrective action or intervention is required.
Reference in Strategy: §3.3.1 Governance Structure, pp.23–25, which establishes the National AI Authority, Interministerial AI Council and related governance bodies; and §3.11.3 Monitoring and Reporting, p.45, which provides for regular KPI monitoring and corrective action.
4. Formal project-delivery assurance
For major public-sector AI initiatives, consideration could also be given to having a formal project-delivery assurance process at key stages of implementation. This would complement the National AI Strategy’s existing governance and risk controls and would provide a more specific check that projects remain within their agreed scope, budget and timetable, that key risks and dependencies are being managed, and that they are ready to move to the next stage. This would help ensure that approval gates consider not only AI-related risks, but also the overall progress and viability of the project.
Reference in Strategy: §3.3.2 Control Framework, p.27, which establishes lifecycle controls and approval gates; and Annex B, AI Use Case Lifecycle and Control Gates, pp.57–59.
5. Requirements and user acceptance
For significant public-sector AI initiatives, it would be useful to ensure that the business and user requirements are clearly defined before procurement or development starts, together with appropriate acceptance criteria. The intended users should also have a meaningful role during design, testing and acceptance, so that the solution being implemented meets the needs for which it was originally intended.
Reference in Strategy: §3.4.2 Use Case Driven Approach, p.28, which requires the problem to be defined before selecting a solution; §3.4.5 Capacity Building and Change Management, p.29; and Annex B, Stage 2 and Stage 3, pp.58–59, concerning design, testing and deployment readiness.
6. Formal change-control mechanism
The National AI Strategy could give more detail on how significant changes to an AI project should be managed during implementation. Changes affecting the scope, requirements, cost, timetable or expected benefits could be documented and assessed before they are submitted for approval at the appropriate level. Significant changes could also trigger a further review where necessary.
Reference in Strategy: §3.3.2 Control Framework, p.27, which requires approval gates before “material modifications” to AI systems; and Annex B, Stage 5, p.59, which provides for adaptation or modification during the lifecycle.
7. Independent assurance at major gates
For major or high-value public-sector AI initiatives, consideration could be given to obtaining independent assurance at key stages of the project lifecycle, especially before procurement, major commitments of resources, deployment and later scaling. The level of such assurance could be based on the financial, operational and wider importance of the initiative.
Reference in Strategy: §3.3 Governance and Controls, p.21, which refers to internal or external assurance; and Annex B, pp.57–59, which establishes the lifecycle control gates.
8. Strengthening the “intelligent client” capability
The National AI Strategy could place more emphasis on the capabilities that public bodies need in order to act as effective and informed owners of AI initiatives. This includes not only understanding the technology, but also being able to define requirements, manage procurement and contracts, oversee suppliers, be actively and effectively involved in testing and acceptance and keep accountability within the public organisation even when implementation is outsourced.
Reference in Strategy: §2.2.4 Skills and Organisational Readiness, p.10, which states that some public organisations lack the internal capability to identify, procure and manage AI systems; and §3.6.3 Public-Sector Capability, p.37, which requires public servants to commission, evaluate and manage AI systems, including where outsourced.
9. Procurement and contract-management capability
Given the likely use of external technology providers and implementation partners for a significant part of AI adoption, the Strategy could give more attention to the capabilities needed to manage these relationships effectively. This could include preparing suitable technical specifications, setting clear and measurable deliverables, having appropriate acceptance arrangements, monitoring supplier performance, ensuring knowledge transfer and making sure that the public body keeps enough control over the system throughout its lifecycle.
Reference in Strategy: §3.4.1 Priority Areas for Government Adoption, p.32, which refers to the transition toward AI-first procurement models; §3.3.2 Control Framework, p.27, concerning procurement and delivery partners; and Objective 8, §2.5.8, pp.17–18, concerning partnerships, knowledge transfer, interoperability and portability.
10. Total lifecycle cost, not only implementation cost
The National AI Strategy could place more emphasis on considering the total cost of an AI initiative over its full lifecycle, rather than focusing mainly on the initial investment. This should include, where relevant, the costs of implementation and integration, infrastructure, licences, support and maintenance, future upgrades, skills, and eventual replacement or decommissioning.
Reference in Strategy: §3.10 Sustainability and Economic Model, p.44, which addresses financial resilience and multi-year renewal; and Annex B, Stage 5, p.59, which includes adaptation and decommissioning.
11. Explicit benefits-realisation and stop/continue decisions
The National AI Strategy could place more emphasis on checking whether the expected benefits of significant AI initiatives are actually being achieved. It would be useful for the expected benefits to be identified at the beginning, with a baseline where possible, so that progress can later be measured. If an initiative is not delivering the expected results, or if its cost, risks or performance have changed significantly, there should be a clear process for deciding whether corrective action is enough or whether the initiative should be modified, reduced or brought to an end.
Reference in Strategy: §3.11.1–3.11.4 Outcomes-Focused Measurement, National KPIs, Monitoring and Reporting, Learning and Continuous Development, pp.44–45; and Annex B, Stage 4–5, pp.59–60.
12. Skills and organisational capability
The National AI Strategy could provide more detail on the organisational and professional capabilities that public-sector organisations will need for the effective adoption and management of AI. This should go beyond general AI awareness and technical skills and include the ability to define needs and requirements, assess and select solutions, manage procurement and implementation, oversee external providers, and assess the performance and risks of AI systems throughout their lifecycle.
Reference in Strategy: §2.2.4 Skills and Organisational Readiness, p.10, which notes that some public-sector organisations lack the internal capability to identify, procure and manage AI systems; and §3.6.3 Public-Sector Capability, p.37, which refers to the ability of public servants to commission, evaluate and manage AI systems, including where these are outsourced.
13. AI infrastructure capacity, scalability and sustainability
Given the National AI Strategy’s ambition to develop sovereign and scalable AI capabilities in Cyprus, it could give more attention to the longer-term capacity, scalability, resilience and sustainability of the national AI infrastructure that will be needed. For major initiatives such as G-Cloud and national AI compute and data capabilities, it would be useful to consider from the beginning the expected capacity requirements, the ability to scale, key dependencies, lifecycle and renewal requirements, and how infrastructure investment will remain aligned with future public-sector and national AI needs.
Reference in Strategy: §3.7 Infrastructure, Compute and Digital Sovereignty, p.38, which identifies infrastructure as a foundational prerequisite for AI adoption and states that Cyprus currently lacks a National AI Infrastructure capable of supporting its long-term AI ambitions. It also sets out requirements concerning secure storage, processing capacity, connectivity, secure deployment environments and access to advanced computing resources.
In addition, §3.3.1.4 National AI Infrastructure Committee, p.24, assigns responsibility for strategic oversight of national AI compute resources, infrastructure sustainability, operational performance and related economic models. The Strategy also specifically states, in its implementation section, p.39, that Cyprus is currently in the procurement process for G-Cloud and identifies concrete early deliverables and milestones for its implementation.
14. Data governance, quality and readiness
The National AI Strategy could give more attention to the practical requirements for ensuring that data is ready to support significant AI initiatives. This could include clear responsibility for data ownership and quality, common standards and definitions, interoperability between systems, appropriate arrangements for secure data sharing, and checks that the required data is available and fit for purpose before major AI initiatives move into implementation.
Reference in Strategy: §3.2 Data as a Strategic National Asset (p.19); §3.2.2 Data Governance and Stewardship (p.20); §3.2.3 Interoperability and Secure Data Sharing (p.20); §3.2.4 Data by Design in Public Systems (p.20).
15. Prioritisation of AI Adoption in Sectors of Existing National Strength
The National AI Strategy appropriately identifies a number of priority sectors in which Cyprus already has established economic activity, institutional capacity and comparative advantages. These include public administration, financial services, healthcare, tourism, legal services, education, shipping and entrepreneurship.
This approach is considered appropriate for a small, services-oriented economy. Rather than dispersing limited financial, institutional and human resources across a broad range of sectors, Cyprus should prioritise areas where there is already sufficient sectoral expertise, market demand, data availability and potential for measurable economic or public-sector impact.
A comparable approach can be identified in Singapore’s National AI Strategy 2.0. Singapore does not seek to develop leadership across all possible areas of artificial intelligence. Instead, it concentrates national efforts around defined strategic priorities, including government, industry, research, talent and computing infrastructure, while supporting selected areas and centres of excellence.
It is therefore recommended that the National AI Strategy retain this sectoral prioritisation and strengthen it through a clear implementation framework. For each priority sector, the Strategy should identify specific AI use cases, measurable objectives, responsible authorities, implementation timelines, required investment and expected outcomes.
This would help ensure that sectoral prioritisation moves beyond a general statement of intent and becomes a practical mechanism for allocating resources, coordinating implementation and assessing results.
Reference: Singapore National AI Strategy 2.0, Smart Nation Singapore.
https://www.smartnation.gov.sg/initiatives/national-ai-strategy/
Reference in strategy: § 1.2 The National Strategic Objectives and Priority Sectors p.2
16. Treat Data Architecture as Core National AI Infrastructure
The National AI Strategy correctly identifies data fragmentation as one of the main structural barriers to effective AI adoption in Cyprus.
The proposed approach is particularly important. The Strategy refers to federated data architecture, secure APIs, standardised metadata, sectoral data spaces and controlled access mechanisms, rather than relying on unnecessary centralisation of government and sectoral data.
This should be considered a core strength of the Strategy. Effective AI systems depend on reliable, interoperable and accessible data. Without common standards, secure data exchange mechanisms and clear governance arrangements, investment in individual AI applications is likely to produce fragmented results and limited scalability.
Estonia provides a useful international benchmark. Its AI development builds on an already highly integrated digital-state infrastructure. The Estonian Information System Authority, RIA, operates Bürokratt and continues to develop secure infrastructure that supports AI assistants and digital public services across government.
Cyprus should therefore treat data architecture as a strategic infrastructure priority rather than as a supporting technical issue. The implementation of the National AI Strategy should include clear interoperability standards, common metadata requirements, secure API frameworks, data governance responsibilities and measurable targets for connecting priority public-sector datasets and systems.
This would create the technical foundation required for AI systems to operate across government and would reduce the risk of developing isolated applications that cannot communicate, share data securely or scale across institutions.
Reference: Estonian Information System Authority, Artificial Intelligence.
https://ria.ee/en/state-information-system/artificial-intelligence
Reference in strategy: § 3.2 Data as a Strategic National Asset p.19
17. Adopt a “Build Once, Reuse Across Government” Approach
The National AI Strategy’s proposal to develop shared national AI services and reusable capabilities across ministries is one of its stronger operational elements.
Rather than allowing individual ministries and public authorities to procure similar AI tools independently, the Strategy promotes the development of common capabilities that can be deployed and reused across government. This approach can reduce duplication, lower procurement and maintenance costs, improve interoperability and support more consistent standards for security, data governance and system performance.
The United Kingdom provides a relevant international comparison. Its AI Opportunities Action Plan includes recommendations for greater infrastructure interoperability, code reusability and the development of a scalable government AI technology stack. These recommendations reflect the broader principle that common digital and AI infrastructure can support faster and more coordinated adoption across the public sector.
It is therefore recommended that Cyprus formalise the “build once, reuse across government” principle as a core implementation requirement of the National AI Strategy. Shared components should be developed for capabilities that are common across ministries, including AI assistants, document processing, language technologies, data access services and other horizontal functions.
The implementation framework should also define which authority will own and maintain these shared services, how ministries will access them and under what circumstances separate procurement will be permitted.
This approach would reduce fragmentation and help ensure that public investment in AI creates reusable national infrastructure rather than a series of isolated departmental systems.
Reference: UK Government, AI Opportunities Action Plan: Government Response, Recommendations 41 and 42.
https://www.gov.uk/government/publications/ai-opportunities-action-plan-government-response/ai-opportunities-action-plan-government-response
Reference in strategy: § 3.5 Priority Sectors p.29
18. Introduce a Consolidated and Costed National AI Implementation Plan
The National AI Strategy does not currently provide a consolidated estimate of the financial resources required for implementation.
The Strategy states that budget allocations should be aligned with performance objectives, but it does not present an overall national AI budget or a costed implementation framework covering the main programmes, infrastructure investments and institutional responsibilities.
This gap is also visible in the section on sovereign AI infrastructure, where the Strategy proposes the development of a roadmap, governance model and funding plan. This indicates that important elements of the financing framework remain to be defined after the Strategy is adopted.
International examples show the value of linking strategic ambitions to clearly identified funding commitments. Singapore’s National AI Strategy 2.0 includes concrete programme-level funding, including the S$150 million Enterprise Compute Initiative. France has also linked its AI ambitions to substantial infrastructure investment commitments, including €109 billion announced in 2025.
These figures are not directly comparable with Cyprus and should not be treated as benchmarks for the level of expenditure required. The relevant lesson is that a national AI strategy should provide greater clarity on the expected cost of its ambitions and on how those costs will be financed.
It is therefore recommended that Cyprus publish a consolidated, costed implementation plan alongside the National AI Strategy. This should include estimated capital and operating expenditure, funding sources, expected EU and national contributions, procurement timelines and indicative expenditure by major programme or strategic pillar.
A costed implementation plan would make the Strategy more credible, improve accountability and allow government, Parliament and the public to assess whether the resources committed are proportionate to the stated objectives.
References:
Singapore, National AI Strategy 2.0, Smart Nation Singapore.
https://www.smartnation.gov.sg/initiatives/national-ai-strategy
France, AI Action Summit and AI-related investment commitments, Élysée, 2025.
https://www.elysee.fr/admin/upload/default/0001/18/6cd9e17ec44a1c92e099626f065781cf69fa394e.pdf
Reference in strategy: § 3.3.1 Governance Structure p.22 & 3.7.3 Digital Sovereignty and Strategic Autonomy, p. 39
19. Simplify the Governance Structure and Clarify Accountability
The National AI Strategy establishes a broad governance architecture involving several categories of bodies, in addition to ministry-level responsibilities. While the Strategy assigns roles across these structures, the number of institutions and interfaces involved could create overlapping responsibilities and slow implementation.
The proposed model gives the central Authority a coordinating and gatekeeping role, while ministries retain operational responsibility. At the same time, the Taskforce has a separate role in monitoring implementation. This creates multiple points of interaction between policy coordination, operational delivery, oversight and performance monitoring.
The concern is therefore not that responsibilities are entirely undefined. The main risk is that a complex governance structure may create uncertainty over who is ultimately accountable for decisions, delays, budget execution and delivery outcomes.
Singapore provides a useful international comparison. Its national AI governance model has moved toward stronger top-level coordination, including the establishment of a National AI Council chaired by the Prime Minister. This reflects an effort to strengthen strategic direction and decision-making at the highest level.
It is therefore recommended that Cyprus review whether all proposed governance bodies are necessary and clearly distinguish between strategic oversight, regulatory functions, implementation responsibility and performance monitoring.
The final governance framework should identify one clearly accountable authority for overall delivery, define escalation mechanisms for unresolved issues and minimise duplication between coordinating and monitoring bodies. A simple responsibility matrix should also specify which institution is accountable, responsible, consulted and informed for each major action.
This would reduce execution risk and help ensure that governance arrangements support implementation rather than adding further administrative complexity.
Some critical unanswered questions are:
• Who ultimately owns delivery?
• Who controls the implementation budget?
• Who can stop an underperforming project?
• Who is accountable for missed KPIs?
• How are conflicts between ministries resolved?
Reference:
Singapore, National AI Strategy 2.0, Smart Nation Singapore.
https://www.smartnation.gov.sg/initiatives/national-ai-strategy/
Reference in strategy: § 3.3.1 Governance Structure p.22
20. Replace the “Three Unicorns” Target with Broader Economic Impact Indicators
The National AI Strategy identifies the creation or attraction of “three unicorns” as one of the objectives associated with the proposed AI Innovation Fund. While this provides a visible ambition for the development of the AI ecosystem, unicorn creation should not be treated as a primary indicator of economic success.
A unicorn valuation is primarily the result of private financing rounds and investor expectations. It does not necessarily demonstrate that a company has generated sustainable revenues, created high-productivity employment, developed intellectual property in Cyprus or contributed significantly to exports and the wider economy.
For this reason, the Strategy should place greater emphasis on measurable indicators of underlying economic activity and value creation. These could include AI-related exports, revenue generated by supported companies, intellectual property developed and retained in Cyprus, private follow-on investment, the number and quality of high-productivity jobs created, research commercialisation and the proportion of supported companies that successfully scale into international markets.
The objective should not necessarily be to remove ambition around developing globally competitive technology companies. Rather, the success of the AI Innovation Fund should be assessed through a broader set of economic indicators that measure whether public support is creating sustainable economic value in Cyprus.
It is therefore recommended that the “three unicorns” target be treated as a secondary ambition rather than a core economic KPI and that the Strategy introduce a balanced set of measurable indicators covering company growth, exports, intellectual property, private investment and employment.
This would provide a more meaningful basis for evaluating whether public investment in the AI ecosystem is producing sustainable economic outcomes.
Reference in strategy: § 5. Immediate Steps for the Strategy Launch p.50
21. Strengthen Demand-Side Support Through Public Procurement
The National AI Strategy includes a broad range of measures to support startups and scaleups, including access to funding, computing infrastructure, regulatory sandboxes, testbeds and other support mechanisms.
These measures are important, but they remain largely supply-side in nature. They focus on helping companies build products, access infrastructure and navigate regulation. Less emphasis is placed on creating domestic demand for those products and helping innovative companies secure their first significant customers.
The United Kingdom’s AI Opportunities Action Plan provides a useful comparison. It places greater emphasis on the role of the state as a customer of AI solutions, including procurement reform and the use of government purchasing power to support innovation and shape emerging AI markets.
For Cyprus, this could be particularly relevant. A small domestic market can make it difficult for startups to secure early reference customers, validate products at scale and demonstrate commercial traction before expanding internationally.
It is therefore recommended that the National AI Strategy complement existing startup support measures with a stronger demand-side policy. This should include mechanisms that make it easier for ministries and public authorities to procure innovative AI solutions from startups and SMEs, launch challenge-based procurement programmes, conduct structured pilots with clear pathways to production, and create opportunities for successful solutions to scale across government.
The objective should not be to add further incubators or support programmes alone, but to create a functioning market in which innovative companies can sell, deploy and scale their solutions.
A stronger procurement and demand-side approach would improve the commercial impact of public support and help convert innovation funding into revenues, reference customers, exports and sustainable company growth.
References:
UK Government, AI Opportunities Action Plan.
https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan
UK Government, AI Opportunities Action Plan: Government Response.
https://www.gov.uk/government/publications/ai-opportunities-action-plan-government-response/ai-opportunities-action-plan-government-response
Reference in strategy: § 3.8 Research, Innovation and Ecosystem Development p.40
22. Differentiate the “3,000 AI Professionals” Target by Skill Category
The National AI Strategy sets a target of approximately 3,000 AI professionals and includes within this figure a wide range of occupational categories, such as AI engineers, data scientists, no-code developers, prompt engineers and certified specialists.
While the ambition to expand Cyprus’ AI talent base is positive, a single headline target risks combining substantially different levels and types of capability. Frontier technical skills, applied AI engineering, data science, no-code development and general AI proficiency serve different economic and institutional needs and should not be treated as equivalent.
The United Kingdom’s AI Opportunities Action Plan places emphasis on first developing an accurate assessment of the national AI skills gap before designing interventions. This reflects the importance of understanding which specific skills are scarce, in which sectors, and at what level of technical depth.
Finland also provides a useful reference through an approach that links skills development with industrial adoption and measurable implementation indicators. This allows talent policy to be connected more directly to the needs of the economy rather than being assessed only through aggregate participation numbers.
It is therefore recommended that Cyprus replace or supplement the headline target of 3,000 AI professionals with a more detailed skills framework. This should distinguish between advanced AI researchers, machine learning and AI engineers, data professionals, applied AI specialists, sector-specific practitioners and broader AI-literate professionals.
The Strategy should also define how each category will be measured, the expected demand from the public and private sectors, and the education, reskilling or talent-attraction mechanisms required to address identified shortages.
This would provide a more accurate picture of Cyprus’ AI capacity and reduce the risk that a quantitative target is achieved without addressing the most important technical and sectoral skills gaps.
References:
UK Government, AI Opportunities Action Plan.
https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan
Finland, national AI and digital policy programme.
https://julkaisut.valtioneuvosto.fi/items/24932639-b776-45a1-85ad-9c084726b0d9/full
Reference in strategy: § 2.5.2 Objective 2: Increase national productivity through responsible AI adoption p.16
23. Measurement and Benefits-Realisation Gap
The CNAI Strategy contains ambitious targets, including AI adoption, productivity, GDP impact, skills and citizen-service improvements.
The challenge is attribution.
For example, productivity improvements cannot automatically be attributed to AI. The CNAI Strategy therefore needs a stronger distinction between:
Inputs → Activities → Outputs → Outcomes → Economic/Societal Impact.
Every major AI programme should have:
• baseline;
• quantified target;
• responsible owner;
• deadline;
• data source;
• evaluation methodology;
• benefits-realisation plan.
Cyprus needs an independent National AI Observatory and Impact Dashboard.
Reference in strategy: § 3.11.1 Outcomes-Focused Measurement) (Annex F – National KPIs and Measurement Framework (sample)
24. AI Adoption Versus Transformation
The CNAI Strategy correctly recognises the danger of fragmented pilots and emphasises scaling proven use cases.
Nevertheless, the number of proposed initiatives is substantial.
Cyprus should avoid measuring success by:
• number of pilots + number of programmes + number of trained people.
The real measurement should be:
• economic value + public-service improvement + productivity + exports + research commercialisation + citizen benefit.
Every major project should therefore pass through a common:
• Business Case → Risk Assessment → Pilot → Independent Evaluation → Scale / Stop process.
25. Public Procurement and Vendor Dependency
The CNAI Strategy appropriately promotes common platforms and reusable AI services. It also envisages shared government AI capabilities and a G-Cloud foundation.
However, procurement needs to become an explicit AI industrial-policy instrument.
Cyprus should use government demand to:
• stimulate local AI companies;
• create first customers;
• encourage European solutions;
• avoid vendor lock-in;
• require interoperability and portability.
The Strategy should therefore establish a National AI Procurement Framework covering model portability, data portability, open standards, cybersecurity, auditability and supplier exit strategies.
Reference in strategy: § 3.7.3 Digital Sovereignty and Strategic Autonomy p.39 & 3.4.1 Priority Areas for Government Adoption p.28
26. Foundation Models, Generative AI and AI Agents
The Strategy recognises generative and agentic AI, but these technologies deserve a dedicated governance framework rather than scattered references throughout the document (indicatively in sections: Tourism and Hospitality Pillar – What this pillar is expected to deliver, 5. Legal Services, Legal Services Pillar – What this pillar is expected to deliver)
Cyprus needs clear national policies for:
• government use of LLMs;
• confidential government information;
• AI agents capable of taking actions;
• hallucination and reliability;
• model evaluation;
• open-source versus commercial models;
• copyright;
• synthetic content;
• deepfakes;
• human oversight.
This is particularly urgent because Article 50 transparency requirements are now applicable from 2 August 2026. Providers and deployers must meet specified transparency requirements concerning AI interaction and AI-generated or manipulated content.
Reference:
https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
27. EU AI Act: Alignment Versus Operational Readiness
The CNAI Strategy explicitly commits Cyprus to EU AI Act compliance and proposes a National AI Compliance Framework.
This is a significant strength.
However, there is an important distinction between:
• strategic alignment and operational regulatory readiness.
Cyprus must ensure that its national framework can actually support:
• market surveillance;
• conformity assessment;
• regulatory sandboxes;
• incident reporting;
• AI literacy;
• fundamental-rights safeguards;
• high-risk AI governance;
• transparency obligations;
• GPAI coordination;
• enforcement.
The EU framework is now moving from preparation to implementation, with governance and GPAI requirements already applicable and transparency obligations commencing in August 2026.
Cyprus should establish a dedicated AI Act Implementation Programme rather than treating compliance primarily as a strategic principle.
Reference in strategy: § 2.3.3 Alignment with European Frameworks p.12
28. Human-Centred AI: Equality, Literacy and Skills for All
Enforce Algorithmic Gender-Bias Auditing: Require all state-deployed or state-procured AI systems to undergo a mandatory “Gender Equality Impact Assessment” to ensure public algorithms do not perpetuate systemic demographic bias. Users – citizens can have an involvement into this by reporting potential biased behavior of in use AI systems.
Launch “AI Literacy for All” Community Workshops: Partner with local municipalities and community centers to run free, non-technical evening/hybrid workshops explaining how everyday AI tools work, data privacy rights, and how to spot AI-generated deepfakes.
Integrate AI Literacy into the elderly Program: Expand existing state programs for senior citizens to include accessible modules on navigating AI-driven public services (e.g., Cyprus Government Gateway /gov.cy) to prevent the digital exclusion of the elderly.
Incorporate AI Ethics into School Curriculums: Mandate the Ministry of Education to introduce basic AI literacy, algorithmic bias awareness, and prompt engineering into the standard public school curriculum starting from Primary school. This can also be used for encouraging the involvement of female students and students coming from vulnerable backgrounds in tech fields.
Fund “AI Transition Scholarships” for At-Risk Workers: Direct specific funding from the EU Just Transition Fund to create fast-track technical and semi-technical AI training paths for workers in retail, tourism, and hospitality sectors with high female and youth employment that face imminent automation.
Provide “Return-to-Work” AI Bootcamps: Create fully subsidized, flexible AI data annotation, project management, and basic programming bootcamps specifically designed for parents returning to the workforce after long-term parental leave.
29. Integration of Gender-Disaggregated Data Collection and Bias Auditing in AI Governance
The National AI Strategy places appropriate emphasis on fairness, non-discrimination and compliance with the EU AI Act. It also assigns an important role to the National Ethics and Values Committee and the wider governance and control framework.
However, the Strategy does not define sufficiently specific operational mechanisms for identifying and mitigating gender and demographic bias in AI systems. This is particularly relevant where training datasets may reflect historical inequalities, occupational segregation or the under-representation of specific population groups.
It is therefore recommended that the National Ethics and Values Committee, in coordination with the National AI Authority, establish a standardised Algorithmic Impact Assessment framework for AI systems developed, deployed or procured by the public sector.
These assessments should explicitly examine gender and demographic bias before deployment and, where appropriate, throughout the lifecycle of the system. They should include reviews of training data, model outputs, error rates and differential impacts across relevant population groups.
The Strategy should also require the systematic collection and reporting of gender-disaggregated indicators in publicly funded AI research, development and deployment. This would align implementation with Action 10.2 of the National Strategy for Gender Equality 2024–2026 and provide measurable evidence on whether AI policies are contributing to, or potentially reinforcing, existing inequalities.
This would strengthen the Strategy’s existing commitments on fairness by translating high-level ethical principles into clear and auditable implementation requirements.
References:
Cyprus National Strategy for Gender Equality 2024–2026, Action 10.2.
Reference in strategy: § 3.3, “Governance and Controls”, including Section 3.3.1.5, “National Ethics and Values Committee”, and Section 3.3.2, “Control Framework”. p.21-27 & 3.9.4, “Fairness and Non-Discrimination” p. 42-43
30. Gender-Responsive Target Setting and Intersectional Inclusion in Workforce Transformation (FutureAI CY)
The National AI Strategy places significant emphasis on talent development, workforce transformation and the creation of approximately 3,000 AI professionals. The FutureAI CY flagship programme is intended to support this objective through stackable micro-credentials and structured upskilling pathways.
However, the current framework does not appear to include specific gender or inclusion targets for participation. This creates a risk that existing inequalities in STEM education and employment could be reproduced within the emerging AI workforce, particularly if participation is measured only through aggregate training numbers.
It is therefore recommended that the FutureAI CY programme introduce clear participation targets for women across its six priority tiers. A minimum participation threshold, for example 40–50%, could be considered, with particular emphasis on women returning to the labour market and female graduates from non-technical disciplines who could transition into applied AI roles.
The National AI Strategy should also provide dedicated and fully or partially subsidised training pathways for groups that may face additional barriers to participation, including women in rural areas, single mothers and women with disabilities. Flexible delivery models, including evening, hybrid and remote learning options, should form part of this approach.
These measures would be consistent with Actions 2.6 and 10.1 of the National Strategy for Gender Equality and with the Second Pillar of the national Disability Strategy.
The objective should be to ensure that the expansion of Cyprus’ AI talent base does not simply increase the overall number of trained professionals, but also broadens participation in the digital economy and reduces existing gender and accessibility gaps.
References:
Cyprus National Strategy for Gender Equality, Actions 2.6 and 10.1.
Cyprus National Disability Strategy, Second Pillar.
References in strategy: § 3.6, “Talent, Skills and Workforce Transformation” p 36-37, including § 3.6.4, “Workforce Augmentation and Transition”, and § 3.6.5, “Attracting and Retaining AI-related Talent” & Annex C, Flagship Programme: “FutureAI CY” p.80.
31. Digital Accessibility and Universal Design Compliance for Citizen-Facing AI Portals
The National AI Strategy places significant emphasis on the use of AI across government, including conversational agents, multilingual access points and the development of the “Digital Citizen 2.0” model.
However, the National AI Strategy does not appear to explicitly require that these citizen-facing AI systems comply with accessibility obligations under the European Accessibility Act and relevant national legislation. This creates a risk that new AI-enabled public services could improve efficiency while still leaving barriers for citizens with disabilities.
It is therefore recommended that all generative AI tools, automated public-service portals and conversational agents deployed by the public sector be required to follow Universal Design principles and comply with the Accessibility of Products and Services Law implementing Directive (EU) 2019/882.
Accessibility requirements should be incorporated from the design and procurement stage rather than treated as an additional feature after deployment. This should include multimodal functionality such as text-to-speech, speech-to-text, high-contrast and keyboard-accessible interfaces, and other assistive technologies appropriate to the needs of citizens with visual, auditory, motor or cognitive impairments.
Where technically feasible and validated for accuracy, the National AI Strategy should also support the development of Cyprus Sign Language-enabled interfaces and other language and accessibility technologies relevant to the local population.
These requirements should be incorporated into public-sector AI procurement standards, technical specifications and acceptance testing, with accessibility performance assessed before systems are made available to the public.
This would ensure that the digital transformation envisioned under “Digital Citizen 2.0” is inclusive by design and consistent with Cyprus’ wider obligations and policies on disability and equal access to public services.
References:
Directive (EU) 2019/882, European Accessibility Act.
Accessibility of Products and Services Law.
Cyprus National Action Plan on Disability, Third Pillar, Action 16.
References in strategy: § 3.4, “AI Adoption Across Government”, including § 3.4.1, “Priority Areas for Government Adoption” p.28-29, Annex C, “Personalised Citizen Journey – Digital Citizen 2.0” p. 61-62.
32. Gender Mainstreaming in Priority Vertical Sectors (Shipping, FinTech, and Healthcare)
The National AI Strategy identifies financial services, healthcare, shipping and maritime among the priority sectors for AI leadership and proposes a range of sector-specific initiatives to accelerate adoption.
However, the current sectoral approach could place greater emphasis on how AI adoption may interact with existing gender disparities. This is particularly relevant in traditionally male-dominated sectors such as shipping and FinTech, as well as in healthcare, where historical data gaps may affect the performance of AI-supported diagnosis, triage and treatment.
For shipping and financial services, it is recommended that sectoral AI initiatives incorporate measurable gender inclusion indicators alongside technological and productivity objectives. AI Industrial Centres of Excellence could be used not only to develop technical capabilities, but also to support more inclusive talent pipelines, monitor participation by gender and track career progression in AI-augmented maritime and financial technology roles.
This approach would be consistent with Actions 14.1 and 14.2 of the National Strategy for Gender Equality and would help ensure that technological transformation does not reinforce existing occupational imbalances.
In healthcare and life sciences, the Strategy should explicitly require that national health data infrastructure and AI-supported clinical systems account for sex- and gender-related differences in health outcomes, biomarkers, symptoms and clinical presentation.
In particular, the proposed Secure National Health Data Repository and Socratic Scaffolding Diagnostic AI framework should include requirements for representative datasets, disaggregated performance testing and ongoing monitoring for differences in diagnostic accuracy and treatment recommendations across relevant population groups.
This would reduce the risk that historical gaps in clinical data are reproduced in AI systems and would strengthen the Strategy’s broader commitments to fairness, safety and non-discrimination.
References:
Cyprus National Strategy for Gender Equality, Actions 14.1 and 14.2.
References in strategy: § 3.5, “Priority Sectors for Leadership” p. 33-36 & Annex C, including initiatives related to Financial Services, Healthcare, Shipping and Maritime p. 64-71 and 82-85.
33. Institutional Representation and Gender Budgeting in National AI Governance
The National AI Strategy establishes a multi-layered governance structure through the National AI Authority, the Interministerial AI Council and the National AI Taskforce, alongside a funding and renewal model for implementation.
However, the current governance framework does not appear to provide formal representation for national gender equality and disability inclusion mechanisms. The funding model also does not explicitly incorporate gender-responsive budgeting or broader demographic impact assessment.
It is therefore recommended that the governance structure include formal representation from the Office of the Commissioner for Gender Equality and the Department for Social Inclusion of Persons with Disabilities, particularly within the Interministerial AI Council and the National AI Taskforce.
This would help ensure that equality, accessibility and inclusion considerations are incorporated at the policy-design and implementation stages, rather than being assessed only after AI systems and programmes have already been developed.
The Strategy should also apply Gender-Responsive Budgeting principles to multi-year national AI expenditure. Major allocations for AI infrastructure, testbeds, innovation programmes, skills initiatives and public-sector deployment should be assessed not only against technological and economic objectives, but also against their distributional impact across different demographic groups.
This approach would be consistent with Actions 1.1 and 1.2 of the National Strategy for Gender Equality and would strengthen accountability over how public AI investment contributes to broader social and economic inclusion.
The objective should be to ensure that AI governance and funding decisions reflect both technological priorities and measurable equality outcomes.
Reference:
Cyprus National Strategy for Gender Equality, Actions 1.1 and 1.2.
References in strategy: § 3.3.1, “Governance Structure”, including § 3.3.1.1, “National AI Authority”, § 3.3.1.2, “Interministerial AI Council”, and § 3.3.1.3, “National AI Taskforce” p. 22-26 & § 3.10.3, “Funding and Renewal Model” p.44.
SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY 2032
Submitted by: REXE Technologies Ltd, trading as REXE (Real Estate Exchange Europe), Nicosia
Contact: Angus Archer Mason, Founder and Managing Director
Date: 31 August 2026
ABOUT THE SUBMITTER
REXE Technologies Ltd is building a regulated digital escrow and settlement platform in Cyprus, to be licensed as an Administrative Service Provider regulated by the Cyprus Bar Association and/or CySEC, with client funds held at a systemic Cypriot credit institution as depository of record. The platform is built for property transfers in the first instance and extends to corporate, marine, aviation and other legal settlements.
The model is not speculative. REXE is built on the architecture of Property Exchange Australia (PEXA), which carries close to 90 per cent of Australian property settlements, has processed more than twenty million settlements, and in the 2025 financial year settled over one trillion Australian dollars, connecting more than ten thousand legal practitioners with some 160 financial, government and statutory bodies. Australia moved from paper settlement rooms to a national digital rail in roughly a decade. No equivalent rail exists in Cyprus, Greece or most of the European Union.
Our positioning is deliberately narrow: infrastructure behind the notary and the advocate. REXE does not practise law and does not hold itself out as a professional adviser. It operates the money rail and the document rail beneath the regulated professional, who retains the legal act and the responsibility for it. Every action with legal or financial effect passes a human approval gate against an append-only approvals ledger. Production infrastructure is hosted in Germany under EU data protection law, while the entity, its licence, its governance and its records remain Cypriot.
DECLARATION OF INTEREST
The comments below concern the Legal Services pillar, in which we would be a market participant. Comment 1, if adopted, would create opportunities for which we and others would be candidates. We make the comments because we consider the underlying gap material, and we would participate in delivering any of them.
COMMENT 1 — ADD TRANSACTIONAL LEGAL SERVICES AND SETTLEMENT TO THE LEGAL SERVICES PILLAR
Strategy reference: Section 3.5, Priority Sector (Legal Services), pp. 34 and 74-76; Annex C, Legal Services.
Comment / Suggestion:
The Legal Services pillar addresses legal information (the Cyprus case-law model, court transcription), legal adjudication (the AI Judge capability) and legal compliance (AIREG, the Digital AML Certification Scheme, NAICF). It does not address legal transactions: conveyancing, property transfer, corporate transactions, and the settlement of funds and title.
We recommend that transactional legal services and settlement be added as a named component of the pillar, with its own use case, deliverables and KPIs, and that the pillar’s measurable targets include time-to-settlement, registry rejection and rework rates, and cost per transaction.
Justification:
Property transfer is the highest-volume, most document-bound and most citizen-facing legal process in the Republic. It is also the process in which the largest sums of consumer money move, the process most dependent on multi-registry coordination between the Department of Lands and Surveys, the Tax Department and DRCOR, and the process where administrative error and delay are most visible to the public.
It is therefore the strongest candidate in the entire pillar for measurable productivity gain, and the pillar currently omits it.
The omission also weakens two of the Strategy’s own commitments. Section 3.4.1 commits the government to AI-first procurement principles by 2032 and Section 3.2.5 proposes a National Intelligent Digital API Fabric, but neither is connected to the transaction that would exercise them at volume. And the pillar’s flagship proposals — an AI Judge for claims under 5,000 euro, a case-law language model, a blockchain registry — are all downstream of, or adjacent to, disputes. A settlement rail acts upstream, on the transactions that generate disputes when they go wrong.
Australia is the available evidence. It did not begin by automating adjudication. It built a settlement rail, and the productivity, fraud-reduction and registry-throughput gains followed from the transaction layer rather than from the courtroom.
COMMENT 2 — RECAST THE DIGITAL AML CERTIFICATION SCHEME AROUND THE POINT OF SETTLEMENT
Strategy reference: Legal Services pillar, pp. 74-76 (Digital AML Certification Scheme); Financial Services and Financial Technology pillar.
Comment / Suggestion:
We support the objective behind the Scheme and share the concerns already raised on this consultation that a certificate cannot discharge an obliged entity’s own customer due diligence, monitoring, sanctions and reporting duties.
We recommend that the Scheme be reframed so that its primary control point is the movement of funds rather than the issuance of a certificate: that is, AML evidence generated, verified and retained at the moment of settlement by a regulated operator that sees both sides of the transaction, rather than a portable credential asserted in advance and relied upon afterwards.
Justification:
A certificate is a point-in-time assertion that begins going stale the moment it is issued. It creates exactly the reliance risk that other contributors have identified, and it concentrates systemic dependence on whoever issues it.
Settlement is a different control point and a better one. At settlement, the source of funds, the destination account, both parties’ identities, the consideration and the registry effect are all present simultaneously and are all verifiable. A regulated escrow operator holding client funds at a supervised credit institution sees both sides of every transaction, which is a materially stronger position than dispersed practitioner client accounts, and it produces a contemporaneous, auditable record available to supervisors without a new certification regime.
This also addresses a consumer harm the pillar does not currently name. Diverted settlement funds are among the most damaging frauds in any property market: the sums are large, the transfers are irreversible, and they arrive at a moment of trust. A controlled rail with verified account details removes the attack surface that email-based settlement instructions create. No certificate does that.
COMMENT 3 — ESTABLISH A LICENSED-ACCESS FRAMEWORK FOR NATIONAL LEGAL AND REGISTRY DATA
Strategy reference: Section 3.2 (Data as a Strategic National Asset); Section 3.2.3; Legal Services pillar (Cyprus case-law model; AIREG).
Comment / Suggestion:
The objective of secure, sovereign and interoperable data will not be achieved by infrastructure alone. It requires a legal framework governing who may train on Cypriot legal and registry corpora, and on what terms.
We recommend the Strategy commit to:
(a) a national position on text-and-data-mining reservation over public legal and registry data;
(b) a licensing regime permitting use by accountable, regulated parties, with verifiable access control and provenance logging;
(c) a requirement that outputs derived from such data be attributable and auditable.
Justification:
Cypriot case law, legislation, professional databases and registry records are a national data asset. At present there is no clear national position on their use as AI training data. Under the EU sui generis database right and the text-and-data-mining reservation available under Directive (EU) 2019/790, Cyprus can assert control over these corpora rather than allow them to be absorbed, unlicensed, into models built elsewhere and sold back into the Cypriot market.
This is a data sovereignty measure and a consumer protection one: it ensures legal outputs originate from accountable professionals rather than unlicensed automated substitutes.
We note that other contributors have questioned whether AIREG’s proposed ledger can establish the ownership and provenance effects claimed for it. We agree, and we would add that the underlying objective is better served here than there. Provenance in legal AI depends on licensed, access-controlled, logged source data — a question of rights and governance — rather than on the architecture of the register that records it.
COMMENT 4 — MAKE REGISTRY INTEROPERABILITY OUTWARD-FACING, NOT ONLY INTER-MINISTERIAL
Strategy reference: Section 3.2.5 (National Intelligent Digital API Fabric); Section 3.4 (AI Adoption Across Government); Annex C, Government and Public Sector.
Comment / Suggestion:
We recommend that registry and agency interfaces be specified from the outset as accessible to licensed private operators under defined conditions, not solely to other government departments.
Justification:
Most transactional value is created at the boundary between the citizen, the regulated professional and the registry. If the Department of Lands and Surveys, the Tax Department and DRCOR expose interoperable, machine-readable interfaces to accountable licensed operators, the private sector will build the citizen-facing productivity layer at no capital cost to the state, and the state retains the standard-setting and supervisory role.
If interoperability stops at the ministry wall, the state will be asked to build and maintain that layer itself, on public budget, in competition with private capital that is willing to carry the delivery risk.
Two further public benefits follow. Lodgements arriving complete, validated and machine-readable address registry rejection and rework at source, which is the principal cause of registry backlog. And transfer fees, capital gains withholding and stamp duty can be computed on statutory methodology and remitted at the moment funds move, rather than assessed and pursued afterwards.
We have mapped the multi-registry lodgement dependencies in the Cypriot property transfer process in detail and would make that analysis available to the Taskforce.
COMMENT 5 — DEFINE AN ACCOUNTABILITY STANDARD CYPRUS CAN CERTIFY
Strategy reference: Section 1.1 (Fundamental Principles); Section 3.3.2 (Control Framework); Section 3.9.6; Annex B (AI Use Case Lifecycle and Control Gates).
Comment / Suggestion:
The principle that people must remain in control is correct but is currently expressed as a value rather than a testable standard. We recommend Cyprus develop a certifiable accountability standard for AI used in regulated legal and financial workflows, covering at minimum:
(a) mandatory human approval gates for actions with legal or financial effect;
(b) separation of the approving and compliance functions (dual control), with self-review expressly excluded;
(c) immutable, append-only approval and provenance records available to regulators;
(d) disclosure of the trust boundary beyond which a system may not act autonomously.
Justification:
We are building to substantially this specification, and we would submit that it is achievable for operators of ordinary size rather than only for large institutions.
Point (b) deserves emphasis because it is the requirement most often omitted. A human approval gate provides no assurance if the same identity can hold both the approving and the compliance role on the same record. The control must be enforced at the point of write, not in the interface.
Point (d) matters for agentic systems specifically, an issue other contributors have raised. The governance question for an agentic system is not only what it produces but what it is permitted to do, and the answer should be a declared, auditable boundary rather than an implicit one.
Codifying this would give the phrase “trusted jurisdiction” in Objective 1 an audit trail behind it, and would be an exportable Cypriot standard rather than an imported one.
ENDORSEMENTS
We support, without repeating, the following positions already on this consultation record:
1. That the Strategy be conformed to the enacted national law implementing Regulation (EU) 2024/1689, and that the respective competences of the National AI Authority and the existing competent authorities be stated explicitly to avoid overlap. As a prospective regulated operator we would answer to several supervisors under the current drafting, with no stated coordination mechanism between them.
2. That EU-resident cloud infrastructure be recognised as satisfying sovereignty and residency requirements in the interim, and that sovereignty be defined by lawful control, portability and exit rather than by physical location.
3. That the treatment of ISO/IEC 42001 be corrected, and that management-system certification not be presented as conformity of an AI system.
Angus Archer Mason
Founder and Managing Director
REXE Technologies Ltd
KEMA BLDG, 5th Floor East, 21 Akademias Avenue, Nicosia, CYPRUS 2107
Σχόλια και Εισηγήσεις ΕΤΕΚ επί της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη – Κύπρος 2032
Εισαγωγή
Σε σχέση με τη Δημόσια Διαβούλευση της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ), η οποία εκπονήθηκε από την Εθνική Εξειδικευμένη Επιτροπή για την Τεχνητή Νοημοσύνη (National AI Taskforce), που συστάθηκε με την Απόφαση του Υπουργικού Συμβουλίου αρ. 97.538, ημερομηνίας 22.1.2025, υπό την προεδρία του Επικεφαλής Επιστήμονα για Έρευνα, Καινοτομία και Τεχνολογία και με τη συμμετοχή έντεκα μελών από τον δημόσιο και ιδιωτικό τομέα, την ακαδημαϊκή και ερευνητική κοινότητα, το ΕΤΕΚ χαιρετίζει την εκπόνηση της Στρατηγικής και συμφωνεί με τη γενική κατεύθυνση, το όραμα και τις βασικές αρχές της.
Ιδιαίτερα θετικά αξιολογούνται η ανθρωποκεντρική προσέγγιση, η έμφαση στην ασφάλεια, στη διαφάνεια, στη διαλειτουργικότητα, στην ανάπτυξη δεξιοτήτων και στη συμμόρφωση με το ευρωπαϊκό κανονιστικό πλαίσιο. Για να καταστεί, ωστόσο, η Στρατηγική πρακτικά εφαρμόσιμη και να αποφευχθεί ο κατακερματισμός δράσεων και πόρων, απαιτείται περαιτέρω εξειδίκευση ως προς την προτεραιοποίηση, την κοστολόγηση, τις θεσμικές αρμοδιότητες, την τεχνική αρχιτεκτονική, τη διαχείριση των υφιστάμενων συστημάτων και τη μέτρηση των αποτελεσμάτων.
Το ΕΤΕΚ προτείνει όπως η Εθνική Στρατηγική δεν περιοριστεί σε γενικές κατευθύνσεις, αλλά συνοδευτεί από δεσμευτικό, κυλιόμενο, συγκεκριμένο, κοστολογημένο και ιεραρχημένο Σχέδιο Εφαρμογής ΤΝ μέχρι το 2032, με σαφή χρονοδιαγράμματα, υπεύθυνους φορείς και μετρήσιμα παραδοτέα, και αναμενόμενα οφέλη ανά δράση.
Παράλληλα, θα πρέπει να προβλέπεται υποχρεωτική Εθνική Αρχιτεκτονική Αναφοράς ΤΝ και Δεδομένων η οποία να καθορίζει ενιαίους τεχνικούς κανόνες για τη διαλειτουργικότητα, τις διεπαφές και τα APIs, τα κοινά πρότυπα δεδομένων και μεταδεδομένων, την ταυτοποίηση και τον έλεγχο πρόσβασης, τη διαχείριση μοντέλων και εκδόσεων, τη φορητότητα και τη δυνατότητα αλλαγής προμηθευτή, σχέδιο επικαιροποίησης των διοικητικών διαδικασιών, των υφιστάμενων πληροφοριακών συστημάτων και της αναγκαίας νομικής βάσης, καθώς και ανεξάρτητος μηχανισμός τεχνικής διασφάλισης και ελέγχου για έργα ΤΝ μεγάλης αξίας, υψηλού κινδύνου ή σημαντικού δημόσιου αντικτύπου.
Ακολουθούν τα σχόλια και οι εισηγήσεις του ΕΤΕΚ, σύμφωνα με τη δομή που καθορίζεται στη Δημόσια Διαβούλευση:
1. Αρ. Άρθρου και εδαφίου: Ενότητες 1.4, 1.5, 3, 4 και 5.
Σχόλιο / Εισήγηση: Να εκπονηθεί, εντός καθορισμένου χρονικού διαστήματος, δεσμευτικό και κυλιόμενο Εθνικό Σχέδιο Εφαρμογής ΤΝ μέχρι το 2032. Για κάθε δράση να καθορίζονται τα παραδοτέα και το χρονοδιάγραμμα, η κεφαλαιουχική και λειτουργική δαπάνη και τα αναμενόμενα οφέλη. Παράλληλα, οι δράσεις να καταταχθούν, κατά σειρά προτεραιότητας, σε θεμελιώδεις εθνικές υποδομές, παραγωγικές εφαρμογές πρώτου κύματος και μακροπρόθεσμες ή ερευνητικές πρωτοβουλίες.
Αιτιολόγηση: Η Στρατηγική περιλαμβάνει γενικό ορίζοντα και ενδεικτικές φάσεις εφαρμογής, χωρίς όμως ενιαίο και επαρκώς εξειδικευμένο σχέδιο ανά δράση, με σαφή ιεράρχηση, κοστολόγηση, συγκεκριμένα παραδοτέα και αναμενόμενα οφέλη. Χωρίς κοστολογημένο σχέδιο εφαρμογής, δεν μπορεί να αξιολογηθεί ούτε η βιωσιμότητα ούτε η δυνατότητα παράλληλης υλοποίησης των προτεινόμενων δράσεων. Η ταυτόχρονη προώθηση μεγάλου αριθμού αρχών, συμβουλίων, κέντρων αριστείας, sandboxes, τομεακών πλατφορμών, υποδομών και μεγάλων έργων δημιουργεί κίνδυνο διασποράς των περιορισμένων ανθρώπινων και οικονομικών πόρων.
Για επενδύσεις μεγάλης κλίμακας σε υπολογιστικές υποδομές ΤΝ να προηγείται τεχνοοικονομική μελέτη σκοπιμότητας, η οποία να εξετάζει το συνολικό κόστος ιδιοκτησίας, τις ενεργειακές και περιβαλλοντικές απαιτήσεις, καθώς και την επιλογή μεταξύ ανάπτυξης εθνικής υποδομής και αξιοποίησης υφιστάμενων ευρωπαϊκών υποδομών.
2. Αρ. Άρθρου και εδαφίου: Ενότητες 2.5, 3.3, 3.9, 5 και Παραρτήματα Α και Γ.
Σχόλιο / Εισήγηση: Να εκπονηθεί Οδικός Χάρτης Νομικής και Κανονιστικής Εφαρμογής, στον οποίο να προσδιορίζεται για κάθε μέτρο κατά πόσο αποτελεί υφιστάμενη νομική υποχρέωση, υποχρέωση ευρωπαϊκού δικαίου ή μέτρο που απαιτεί νέα νομοθεσία, αποσαφηνίζοντας τη σχετική νομική βάση για μητρώα, πιστοποιήσεις, άδειες και πρόσβαση σε δημόσιες υποδομές.
Αιτιολόγηση: Το κείμενο χρησιμοποιεί σε ορισμένα σημεία δεσμευτική διατύπωση για θεσμικές στρατηγικές ΤΝ, μητρώα, πιστοποιήσεις, άδειες και πρόσβαση σε δημόσιες υποδομές, χωρίς να αποσαφηνίζεται πάντοτε η σχετική νομική βάση.
Παράλληλα, στο πλαίσιο του Οδικού Χάρτη να αποσαφηνιστούν η νομική βάση και τα όρια αρμοδιοτήτων της Εθνικής Αρχής ΤΝ σε σχέση με τις υφιστάμενες αρμόδιες εποπτικές αρχές, καθώς και να ενοποιηθεί η ονοματολογία και ο ρόλος όλων των προβλεπόμενων οργάνων.
Να αποσαφηνιστεί επίσης η αναφορά σε «AI Judge Capability», ώστε να είναι σαφές ότι τα σχετικά συστήματα έχουν αποκλειστικά υποβοηθητικό χαρακτήρα, με διατήρηση της ανθρώπινης εποπτείας και με σαφή διατήρηση της ανθρώπινης εποπτείας και της δικαιοδοτικής αρμοδιότητας του φυσικού δικαστή.
3. Αρ. Άρθρου και εδαφίου: Ενότητες 3.2, 3.4.4, 3.7, 4.2 και Παράρτημα Β.
Σχόλιο / Εισήγηση: Οι αρχές και τεχνικές κατευθύνσεις που ήδη περιλαμβάνονται στη Στρατηγική να εξειδικευτούν και να ενοποιηθούν σε υποχρεωτική Εθνική Αρχιτεκτονική Αναφοράς ΤΝ και Δεδομένων για όλα τα δημόσια έργα ΤΝ. Η Αρχιτεκτονική να καθορίζει ελάχιστες απαιτήσεις για τη διαλειτουργικότητα, τις διεπαφές και τα APIs, τα κοινά πρότυπα δεδομένων και μεταδεδομένων, την ταυτοποίηση και τον έλεγχο πρόσβασης, τη διαχείριση μοντέλων και εκδόσεων, την παρακολούθηση απόδοσης, τη φορητότητα και τη δυνατότητα αλλαγής προμηθευτή. Η συμμόρφωση με την Αρχιτεκτονική να ελέγχεται πριν από την προκήρυξη και πριν από την παραγωγική λειτουργία κάθε έργου.
Αιτιολόγηση: Η Στρατηγική αναγνωρίζει την ανάγκη κοινών προτύπων, επαναχρησιμοποίησης, διαλειτουργικότητας και φορητότητας. Για να εφαρμοστεί, όμως, στην πράξη η αρχή «build once, reuse everywhere», οι σχετικές πρόνοιες πρέπει να μετατραπούν σε ενιαίες, δεσμευτικές και ελέγξιμες τεχνικές απαιτήσεις. Διαφορετικά, υπάρχει κίνδυνος διαφορετικών ερμηνειών από τους φορείς υλοποίησης, δημιουργίας νέων απομονωμένων συστημάτων, μη συμβατών διεπαφών και εξάρτησης από συγκεκριμένους προμηθευτές.
4. Αρ. Άρθρου και εδαφίου: Ενότητες 2.2.2, 3.2, 3.4, 3.7 και Παράρτημα Γ.
Σχόλιο / Εισήγηση: Κάθε έργο ΤΝ στον δημόσιο τομέα να περιλαμβάνει κοστολογημένο σχέδιο ενσωμάτωσης με υφιστάμενα συστήματα και ανασχεδιασμού διαδικασιών (Legacy Integration and Process Redesign Plan), με συγκεκριμένο χρονοδιάγραμμα για τον καθαρισμό και τον μετασχηματισμό δεδομένων, τη δημιουργία διεπαφών και APIs, τον ανασχεδιασμό διοικητικών διαδικασιών, την εξάλειψη διπλών καταχωρίσεων, την ενοποίηση ή αντιστοίχιση μητρώων, ώστε να αποτραπεί η ενίσχυση υφιστάμενων αδυναμιών από τη χρήση ΤΝ σε παρωχημένα συστήματα.
Αιτιολόγηση: Οι περισσότερες εφαρμογές ΤΝ εξαρτώνται από υφιστάμενα συστήματα διαχείρισης εγγράφων, υποθέσεων, πληρωμών, ταυτοποίησης υγείας και διοικητικών μητρώων. Η εισαγωγή ΤΝ πάνω σε παρωχημένα, μη διαλειτουργικά ή προβληματικά συστήματα δεν αντιμετωπίζει τις βασικές αδυναμίες και ενδέχεται να τις ενισχύσει.
5. Αρ. Άρθρου και εδαφίου: Ενότητες 3.3.2, 3.9, 3.11, 3.13 και Παράρτημα Β.
Σχόλιο / Εισήγηση: Το προβλεπόμενο πλαίσιο πυλών ελέγχου να εξειδικευτεί με υποχρεωτική ανεξάρτητη τεχνική διασφάλιση από φορέα ανεξάρτητο από τον ανάδοχο και την ομάδα υλοποίησης για έργα ΤΝ υψηλού κινδύνου, μεγάλης αξίας ή σημαντικού δημόσιου αντικτύπου. Η διασφάλιση να πραγματοποιείται υποχρεωτικά πριν από την προκήρυξη, πριν από την παραγωγική λειτουργία και πριν από ουσιώδη αλλαγή του μοντέλου, του σκοπού ή του πεδίου χρήσης. Να βασίζεται σε προκαθορισμένα και δημοσιευμένα κριτήρια για την αρχιτεκτονική, τα δεδομένα, την ασφάλεια, τη διαλειτουργικότητα, την ανθρώπινη εποπτεία, την προσβασιμότητα, την απόδοση, τη μεροληψία, την επιχειρησιακή ετοιμότητα και το συνολικό κόστος ιδιοκτησίας.
Αιτιολόγηση: Οι πύλες ελέγχου και η δυνατότητα εσωτερικής ή εξωτερικής διασφάλισης που προβλέπει η Στρατηγική αποτελούν θετική βάση. Για έργα, όμως, με αυξημένο κίνδυνο, κόστος ή επίδραση στους πολίτες, η τεχνική αξιολόγηση πρέπει να είναι υποχρεωτική, να διενεργείται από φορέα ανεξάρτητο από τον ανάδοχο και την ομάδα υλοποίησης και να βασίζεται σε ενιαία κριτήρια αποδοχής. Η προσέγγιση αυτή μειώνει τον κίνδυνο τεχνικής αστοχίας, υπέρβασης κόστους, σύγκρουσης συμφερόντων και λειτουργίας συστημάτων χωρίς επαρκή τεκμηρίωση.
6. Αρ. Άρθρου και εδαφίου: Ενότητες 1.5, 3.5, 5 και Παραρτήματα Γ και ΣΤ.
Σχόλιο / Εισήγηση: Να ενοποιηθούν και να τεκμηριωθούν οι ποσοτικοί στόχοι υιοθέτησης ΤΝ, με σαφή ορισμό του δείκτη, ενιαία βάση αναφοράς, ημερομηνία-στόχο και πηγή δεδομένων. Ειδικότερα, να αποσαφηνιστεί η αναφορά στον στόχο 75% της Ψηφιακής Δεκαετίας, ο οποίος αφορά συνδυαστικά υπολογιστικό νέφος, ανάλυση μεγάλων δεδομένων ή/και ΤΝ και όχι αποκλειστικά υιοθέτηση ΤΝ.
Αιτιολόγηση: Η Στρατηγική χρησιμοποιεί διαφορετικές βάσεις αναφοράς και ημερομηνίες για τον στόχο υιοθέτησης ΤΝ και παραπέμπει στον στόχο της Ψηφιακής Δεκαετίας χωρίς να αποσαφηνίζεται η αντιστοίχιση των δεικτών. Για να είναι οι στόχοι ελέγξιμοι και μετρήσιμοι, απαιτείται ενιαία μεθοδολογία, σαφής πηγή δεδομένων και συνεπής χρονικός ορίζοντας.
Να εξεταστεί επίσης η μετατροπή του Παραρτήματος ΣΤ σε πλήρη πίνακα παρακολούθησης, με ορισμό δείκτη, βάση αναφοράς, πηγή, ενδιάμεσο και τελικό στόχο, αρμόδιο φορέα και συχνότητα μέτρησης.
The Strategy is ambitious and contains many strong elements, particularly in relation to public-sector adoption, data and compute infrastructure, responsible AI, skills, governance and sectoral transformation. The comments below focus on a small number of areas where the Strategy could be strengthened further, especially to ensure that Cyprus builds not only capacity to adopt AI, but also long-term capacity to create AI knowledge, technologies and future industries.
A national AI research strategy should support both research serving today’s economy and research capable of creating tomorrow’s economy.
1. Distinguish AI-adoption priorities from scientific and technological leadership
The eight “Priority Sectors for Leadership” are selected largely on the basis of GDP contribution and exposure to AI-driven productivity gains. These are appropriate criteria for identifying sectors where AI adoption should be accelerated, but they are not necessarily the same criteria that should determine where Cyprus can achieve international scientific or technological leadership.
For example, tourism is clearly an important AI-adoption priority: AI can improve demand forecasting, personalisation, resource management and SME productivity. This does not necessarily imply that Cyprus should concentrate frontier-research resources on becoming a world leader in tourism AI. By contrast, an area such as maritime autonomy could potentially combine an existing Cypriot industrial ecosystem, real test environments, frontier research and exportable technology.
Suggestion: distinguish explicitly between Priority Sectors for AI Adoption and Transformation and a smaller number of Scientific and Technological Leadership Missions. Leadership missions should be selected through a transparent critical-mass and comparative-advantage assessment, considering existing excellence, talent, unique national assets/testbeds, European leverage, global market potential, cross-sector spillovers and long-term sustainability.
2. Elevate Frontier & Foundational AI and introduce AI for Science and Engineering
Section 3.8 and Annex D appropriately recognise foundational AI, but the research architecture remains predominantly applied and sector-oriented. Foundational AI would be better treated as a horizontal national scientific capability, rather than one vertical focus area alongside healthcare, telecommunications or energy.
The Strategy should also explicitly recognise AI for Science and Engineering: the use of AI to generate scientific discoveries and new engineering solutions, rather than only to improve existing services and processes.
Suggestion: organise national AI research around three complementary modes:
• Frontier and Foundational AI (“Science for AI”) – investigator-led research advancing AI itself;
• AI for Science and Engineering – AI-enabled scientific discovery and engineering design; and
• Mission-driven AI R&D – translation of AI into strategic national challenges.
Frontier research should retain a sufficiently bottom-up, excellence-based component so that promising future directions are not limited to a static list of technologies chosen in 2026.
3. Define the National AI Research Fund, AI ERC Bridge and research-talent pipeline more concretely
The proposed National AI Research Fund and AI ERC Bridge could become major instruments for building long-term national AI capability, but their design is currently under-specified.
Suggestion: structure the Research Fund as a portfolio with separate instruments for frontier AI, AI for Science, strategic missions, research translation/proof-of-concept, shared research infrastructure and international research talent. Different instruments should use different evaluation criteria.
The AI ERC Bridge should also be clarified as part of a complete excellence pipeline:
prepare -> bridge/resubmit -> attract -> establish -> retain
In addition to proposal and attraction support, the national framework should address long-term retention and career stability, so that internationally excellent researchers and the teams they build are not lost when externally funded projects end. This issue extends beyond AI and should ideally connect to broader national research-career policy.
4. Strengthen Autonomous Systems into Embodied AI, Robotics and Autonomous Systems, including physical research infrastructure
Annex D already identifies Autonomous Systems and the Strategy proposes an Autonomous Systems Park. This could be strengthened into a more ambitious frontier programme in Embodied AI, Robotics and Autonomous Systems.
Relevant research includes robot learning, manipulation and loco-manipulation, multimodal/tactile perception, learning reusable skills, planning, continual adaptation, safe autonomy, sim-to-real, human-robot collaboration and multi-agent systems.
These capabilities have strong spillovers across several existing priorities: maritime inspection and autonomy; energy/water infrastructure; environmental monitoring; agri-food and field robotics; rehabilitation and assistive healthcare; and security/emergency-response systems.
Suggestion: recognise that AI research infrastructure is not limited to GPUs and data. Frontier robotics also requires shared physical experimental infrastructure – robotic platforms, sensors, laboratories, field/marine systems, instrumented test environments, research engineers, maintenance and technology-renewal budgets. A federated national infrastructure based on existing capability may be more efficient than duplicating expensive equipment.
5. Strengthen the Energy-Environment focus into AI for Climate, Energy, Water and Sustainable Island Systems, and explicitly consider Agri-food
Focus Area 1 already addresses water scarcity, renewable energy, climate impacts, smart grids, irrigation and resource optimisation. The current emphasis is mainly on prediction, monitoring and optimisation. Cyprus could also exploit AI for scientific and engineering discovery.
For example, using AI to optimise an existing desalination plant can provide important near-term value; using AI-assisted discovery to develop better desalination membranes, energy-storage materials, photovoltaic materials or anti-fouling technologies could generate exportable IP and future industries.
Suggestion: consider a mission such as AI for Climate, Energy, Water and Sustainable Island Systems, combining AI-enabled prediction/control with scientific discovery and engineering design.
Agri-food should also be explicitly reconsidered. Although agriculture may contribute less to current GDP than major service sectors, it is strategically important for food security, water demand, climate resilience, rural development and high-value local production. Rather than simply adding a ninth equal “pillar”, Agri-food could be recognised as an important AI-adoption and innovation domain linked strongly to the energy-water-climate and robotics missions.
6. Use existing capability first and define selective strategic autonomy
The Strategy proposes several new national bodies, hubs, committees and Centres of Excellence. Many of the functions are important, but creating new entities can duplicate existing capability and fragment a limited national pool of specialised talent.
Suggestion: adopt an existing-capability-first principle. Before establishing a new institution or Centre of Excellence, map the relevant capability already present in universities, existing Centres of Excellence, research organisations, regulators and European infrastructures. Use federated structures, competitive designation and shared infrastructure where these can deliver the function effectively.
Similarly, “AI sovereignty” should be operationalised as selective strategic autonomy. Cyprus should define what it must own, control, understand, keep portable/interoperable, access through European infrastructure, or procure commercially. National compute investments should follow demonstrated workloads and include utilisation, lifecycle cost, energy and renewal considerations, while leveraging EuroHPC and the European AI Factory ecosystem where scale is more efficiently obtained at European level.
7. Strengthen research-to-innovation pathways, implementation and measurable KPIs
The Entrepreneurship and Innovation pillar contains promising measures, but the complete pathway from frontier research to scalable deep-tech companies should be made more explicit:
discovery -> proof of concept -> IP -> spin-off/startup -> first customer -> follow-on investment -> international scale-up
Possible instruments include proof-of-concept grants, researcher-entrepreneurship mechanisms, predictable IP arrangements, public-sector first-customer/testbed opportunities and strong links to European scale-up instruments.
Implementation should also be more auditable. Annex F is explicitly indicative, while the Strategy contains precise headline targets. Some targets/timelines also require reconciliation – for example, the Strategy refers in different places to 50% and 75% AI-adoption targets by 2032, and to ministerial AI strategies being updated every three years versus annually.
Suggestion: for each major objective define:
baseline -> 2028 milestone -> 2030 milestone -> 2032 target -> methodology -> data source -> accountable owner -> corrective trigger
Separate KPI families should cover adoption/productivity, scientific excellence, research talent, innovation/commercialisation, infrastructure, trust/compliance and strategic missions. Finally, the 2032 Strategy should remain technology-neutral at the strategic level, with specific bets such as particular model architectures or platforms handled through shorter rolling implementation roadmaps.
Concluding comment
The Strategy is already strong in describing how Cyprus can become a responsible and productive user of AI. Its long-term impact could be increased further by answering equally clearly:
In which areas will Cyprus create internationally significant AI knowledge and technologies, rather than primarily adopt technologies created elsewhere?
A strong model for Cyprus would combine broad AI adoption, open excellence-based frontier research, and concentrated investment in a small number of evidence-based scientific and technological missions with sufficient critical mass to become internationally distinctive.
The release of the Cyprus National AI Strategy for public consultation represents, in our view, an important step forward for Cyprus. Moving beyond individual applications of artificial intelligence toward a coordinated national framework matters if Cyprus is to approach one of the most significant technological transformations of our time in a systematic, deliberate and economically meaningful way.
The importance of such a strategy should not be judged solely by whether every target can already be predicted with precision. Artificial intelligence is developing rapidly, its applications are spreading unevenly across sectors and firms, and our understanding of its full macroeconomic effects remains incomplete. A national strategy must therefore perform a more fundamental function: establish a credible direction, build the capabilities needed for adoption, provide an institutional framework within which experimentation can occur, and create mechanisms through which implementation can be measured and progressively improved.
Read through an economic and academic lens, several features of the Cyprus Strategy are particularly important.
——A strategy of focus rather than technological breadth——-
First, the broad architecture of the Strategy is economically sound.
Cyprus does not attempt to compete across every dimension of artificial intelligence. Such an objective would be neither realistic nor economically efficient for a small economy. Instead, the Strategy follows a logic of focus and differentiation, concentrating attention on sectors in which Cyprus already possesses significant economic weight, institutional capabilities or established sectoral strengths. These include financial and professional services, shipping, tourism, healthcare, education and government. At the same time, the Strategy treats data, infrastructure, skills, research, governance and trusted AI as shared enabling capabilities that can support adoption across these sectors. This distinction is important. The economic value of AI for Cyprus will not necessarily arise from attempting to reproduce the complete global AI value chain domestically. It is more likely to arise from becoming exceptionally capable at adopting, adapting and deploying AI in areas in which Cyprus already possesses economic, institutional or sector-specific advantages. The Strategy’s architecture is therefore consistent with the broader logic appropriate to small European economies: coordinated adoption, shared infrastructure, human-capital development, public-sector transformation and credible governance.
The associated concept of sovereign capability through partnerships is particularly relevant. Strategic autonomy should not be interpreted as requiring Cyprus to develop every AI model, semiconductor, cloud platform or technological capability domestically. For a small economy, this would be neither feasible nor desirable. A more useful interpretation of strategic autonomy is the capacity to maintain sufficient knowledge, control, resilience and freedom of action while drawing on European and international partnerships to obtain technological capabilities and scale that cannot efficiently be produced domestically.
This also places institutional capability at the center of the economic discussion. Data governance, interoperability, procurement capability, technological assurance, cybersecurity and regulatory certainty are sometimes treated mainly as constraints surrounding innovation. Properly designed, however, they are also part of the infrastructure through which innovation can spread and scale. If public institutions cannot procure AI effectively, if organizations cannot access appropriate data, if systems cannot communicate with one another, if firms remain uncertain about regulatory requirements, or if the workforce lacks the capabilities required to use new technologies productively, technological availability alone will not generate economic transformation.
The institutional foundations of adoption are therefore not peripheral to the Strategy. They are part of its economic mechanism.
——-The economic evidence for AI is becoming stronger——
Second, the microeconomic and firm-level evidence supporting the proposition behind strategies of this kind has strengthened substantially.
AI can raise productivity and support innovation at the level of workers and firms and, through these and other channels, may eventually expand the productive capacity of the wider economy. What remains considerably less certain is the magnitude, timing and distribution of those effects at the aggregate level. Three recent studies illustrate different links in a possible transmission chain running from individual productivity through firm growth to entrepreneurship and the creation of new economic activity.
Brynjolfsson, Li and Raymond (2025), examining the introduction of generative AI in a real workplace, find meaningful productivity gains associated with the technology.
Babina, Fedyk, He and Hodson (2024) move the analysis to the firm level. They show that firms investing in AI subsequently experience stronger growth in sales, employment and market value, with product innovation representing an important channel.
Gofman and Jin (2024) highlight another mechanism with particular relevance for national policy. Their evidence indicates that the loss of AI professors reduces AI startup formation among affected students, consistent with the proposition that university-based AI knowledge can support entrepreneurship and the creation of new firms.
These studies should not be interpreted as establishing a mechanical sequence through which every AI investment eventually generates economic growth. Rather, they illustrate different links in a possible transmission chain: improved capabilities at the individual level can affect organizations; organizational capabilities can contribute to innovation and growth; and knowledge creation and human capital can contribute to entrepreneurship and new economic activity. This evidence sits alongside a growing body of work from institutions such as the OECD and IMF examining the potential aggregate productivity implications of artificial intelligence. The direction of the evidence is increasingly important. The difficult question is no longer simply whether AI can affect productivity or innovation. There is now substantial evidence that, under appropriate circumstances, it can. The more difficult economic question is how those gains propagate across an entire economy.
—–From individual productivity to national economic performance——
This distinction is central to evaluating any national AI strategy. We are becoming considerably better at measuring what artificial intelligence can achieve at the level of particular tasks, workers and firms. We know much less about how these effects ultimately aggregate into economy-wide productivity, output and welfare.
Adoption is only the beginning of the transmission mechanism. A worker becoming more productive through AI does not automatically make the entire firm proportionately more productive. Task-level productivity gains need to be accompanied by organizational redesign, complementary investments in technology and infrastructure, changes in workflows, new managerial practices and investment in human capital. Those firm-level changes must then become sufficiently widespread to matter at the aggregate level. Successful firms may innovate, develop new products, enter new markets and generate new forms of activity. New firms may emerge. Knowledge and technologies may spill over across sectors. Workers may move between organizations and transfer expertise. Public-sector applications may improve the quality or efficiency of services. New capabilities may reduce costs, improve decision-making and allow existing resources to be deployed more effectively. Only as these different mechanisms accumulate does AI have the potential to produce a substantial effect on aggregate productivity and potential output. The transmission is therefore neither instantaneous nor automatic. It depends on skills. It depends on data readiness. It depends on organizational redesign and capital investment. It depends on how broadly adoption spreads across firms rather than remaining concentrated among a small number of leading organizations. It depends on institutional capability. And ultimately, it depends on execution.
This is where the history of previous general-purpose technologies becomes instructive. Their largest economic effects were often realized only after significant complementary investments in new processes, organizational structures, skills and intangible capital. Brynjolfsson, Rock and Syverson (2021) describe this phenomenon through the concept of the productivity J-curve: transformative technologies may require substantial complementary investment before their full productivity effects become visible in measured economic statistics. AI may follow a similar logic. The economic model of AI, in other words, is still being written. That observation should not be interpreted as an argument for inaction. Rather, it helps explain why a national strategy should combine ambition with experimentation, investment, measurement and continuous learning.
——-Economic value will not necessarily appear in a single statistic—–
A further complication is that the economic effects of AI are unlikely to appear through one channel or in one indicator. Some benefits may eventually register clearly in measured productivity and output. Others may emerge through the creation of new firms, intellectual property, human capital, technological capabilities, knowledge spillovers, improved public services or greater economic and institutional resilience. Some effects may be relatively easy to quantify. Others may be difficult to anticipate before the relevant applications emerge.
The economic impact of AI may therefore become multidimensional before it becomes fully measurable. This point is important when considering the headline macroeconomic ambitions contained in the Strategy. The Strategy refers to ambitions of up to 15% improvement in productivity relative to the baseline trajectory and 12% expansion in GDP associated with AI-enabled transformation. The scale of these eventual gains clearly matters. It matters for economic analysis, but it also matters for determining the appropriate scale, sequencing and allocation of investment.
At the present stage, however, we believe these figures are more appropriately interpreted as strategic scenarios or targets rather than empirically established forecasts. This distinction strengthens rather than weakens the economic case for the Strategy. A forecast implies a particular baseline, transmission mechanism, time horizon and set of behavioral and economic assumptions. Given how rapidly AI technology and adoption are evolving, considerable uncertainty surrounds each of these elements.
An appropriate next step would therefore be to progressively underpin these headline ambitions with a Cyprus-specific scenario and impact-assessment framework. Such a framework could make explicit the assumptions underlying different scenarios, the baseline trajectory against which improvements are measured, the mechanisms through which AI is expected to affect different parts of the economy and the time horizon over which those effects could reasonably emerge. Importantly, this need not involve pretending that the economic effects of AI can already be estimated with false precision. Instead, the framework could initially operate through scenarios, sensitivity analysis and ranges of possible outcomes. As implementation advances and Cyprus-specific evidence becomes available, it could then be progressively calibrated and refined.
This would create a feedback mechanism between strategy, implementation and evidence.
——Uncertainty does not invalidate the strategic direction——-
Uncertainty over magnitude does not invalidate the direction of the Strategy. It does mean that the scale, sequencing and prioritization of investment should evolve with the available evidence. Even more moderate but sustained improvements in productivity, innovation, public-sector efficiency, human capital and the creation of new economic activity can accumulate into substantial economic and social value over time. The strategic case for AI therefore does not need to depend on achieving one particular GDP number or one particular productivity estimate. The more fundamental question is whether AI can materially strengthen productivity, innovation and economic capability. The available evidence increasingly suggests that it can. The Strategy provides Cyprus with a framework within which it can build capabilities, accelerate adoption, strengthen institutions, experiment, learn and gradually identify the applications that produce the greatest economic and societal value.
Implementation itself can also generate another important asset: Cyprus-specific evidence. If appropriately accompanied by rigorous evaluation, implementation will allow policymakers and institutions to observe where adoption succeeds, where it fails, which complementary investments matter, which sectors respond most strongly, and which interventions generate the highest economic and social returns. That evidence can then be used to improve assumptions, refine priorities and redirect resources toward interventions that work. The Strategy should therefore be viewed not simply as a fixed plan extending to 2032, but as a framework within which learning and economic calibration can occur continuously.
—–Why the opportunity is particularly relevant for Cyprus——-
This consideration is especially important because of the structure of the Cypriot economy. Cyprus is a small, highly service-oriented and internationally connected economy. Financial services, professional services, shipping, tourism, healthcare, education and public administration are all activities in which information, expertise, judgment and knowledge play central roles. These are precisely the types of activities in which artificial intelligence can potentially alter how work is performed, how information is processed, how decisions are made and how services are delivered. This does not mean that every occupation or organization will be transformed in the same way. Nor does it mean that technological adoption alone guarantees productivity gains. It does, however, mean that Cyprus has a direct economic interest in developing the capabilities required to participate effectively in this transformation. Standing still while the transformation unfolds would itself constitute a strategic choice. The available evidence is sufficiently strong to justify action. At the same time, considerable uncertainty remains regarding the magnitude, timing and distribution of the eventual gains. These two conclusions are not contradictory. Taken together, they make the case for combining strategic ambition with implementation, measurement, learning and continuous economic calibration. The Strategy provides a structure through which Cyprus can do precisely that.
——From strategic architecture to implementation discipline——
Setting the direction is therefore an important first step. The next challenge is to translate that direction into measurable economic and societal value. The Strategy already provides a credible foundation. Its emphasis on selected sectors, trusted AI, human capital, shared infrastructure and sovereign capability through European partnerships aligns well with Cyprus’s economic structure and strategic position.The next stage can build on this foundation by further strengthening the connection between strategic architecture and implementation discipline.
One dimension is regulatory readiness. With the European Union’s AI regulatory framework becoming operational, implementation of the Strategy can be aligned with the evolving requirements of Regulation (EU) 2024/1689. Connecting governance, procurement, risk classification, transparency, human oversight, AI literacy, regulatory sandboxes and post-market monitoring with the European regulatory framework can reinforce the Strategy’s existing emphasis on trusted and responsible AI. Regulatory readiness should not be viewed solely as a compliance exercise. For firms considering investment and for public organizations deploying AI, legal and regulatory certainty can itself form part of the institutional infrastructure supporting adoption. Keeping the implementation roadmap aligned with the evolving European regulatory timetable can therefore support more consistent implementation across the public and private sectors while reinforcing institutional credibility and investor confidence. In this sense, trusted AI and economic development should not be regarded as competing objectives. Proper governance can contribute to the conditions under which adoption becomes sustainable and scalable.
——Building a measurable implementation framework——
A useful next step would consequently be the progressive translation of the Strategy’s high-level objectives into an increasingly measurable investment and delivery framework. Several elements will be particularly important.
First, institutional responsibilities need to be clearly allocated. AI policy cuts across digital government, education, research, regulation, public administration, industrial policy and sector-specific responsibilities. Effective implementation therefore requires clarity regarding who is responsible for delivery and accountability.
Second, implementation should be supported by a multiannual and prioritized funding framework. The economic logic of AI investment depends not only on how much is spent, but also on sequencing and complementarity. Infrastructure without skills, skills without adoption, or isolated projects without scalable data and governance arrangements may generate limited returns.
Third, Cyprus will need appropriate common data and computing infrastructure. These are enabling capabilities rather than ends in themselves, and investment should be assessed according to how effectively it supports high-value applications.
Fourth, public-sector implementation requires an AI-ready procurement framework capable of acquiring technologies while managing technological, financial, operational and regulatory risks.
Fifth, the country should progressively establish measurable sector-level indicators of adoption, productivity and outcomes. National indicators are useful, but sectoral measurement will be required to understand where value is actually being created.
Sixth, particular attention should be paid to diffusion toward small and medium-sized enterprises. Aggregate productivity effects will depend not only on what the largest or technologically most advanced organizations can achieve, but also on how widely useful applications diffuse throughout the economy.
Finally, implementation should incorporate evaluation of economic and societal outcomes.
The purpose of evaluation should not merely be to determine whether projects were completed or funds were spent. It should establish whether interventions changed adoption, productivity, service quality, innovation, human capital or other relevant outcomes, and whether the value generated justified the resources deployed.
This is the point at which strategy becomes economic policy.
——Direction, evidence and learning——
The case for action is therefore strong, but it does not rest on a single headline GDP or productivity figure. The Strategy gives Cyprus a framework for progressively translating artificial intelligence into higher productivity, stronger firms, improved public services, new knowledge-intensive economic activity, better human capital and greater institutional capability. Not all of these benefits will materialize immediately. Not all will be easily measurable. And not every AI investment will succeed. That is precisely why implementation should be accompanied by measurement, experimentation and evidence-based prioritization.
The objective should be to discover where AI produces genuine value for Cyprus and then create the conditions for those gains to diffuse throughout the economy. There is an important balance to maintain. Excessive certainty about the eventual macroeconomic effects would not be justified by the evidence available today. But excessive caution would carry its own costs if it prevented Cyprus from building capabilities while the technological environment continues to evolve. A more appropriate approach is disciplined ambition: establish the direction, invest in the enabling capabilities, implement, measure the results, learn from them and continuously recalibrate.
Seen from this perspective, the Cyprus National AI Strategy 2032 should not be assessed solely as a prediction of what the Cypriot economy will look like in 2032. Its deeper value lies in providing a framework through which Cyprus can prepare for, participate in and progressively shape a major technological transformation.
The direction has now been set. The challenge is to convert that direction into measurable economic and societal value—and to allow evidence generated along the way to determine how Cyprus proceeds.
——–Sources——-
[1] Brynjolfsson, E., Li, D. & Raymond, L. (2025). “Generative AI at Work.” Quarterly Journal of Economics, 140(2), 889–942.
[2] Babina, T., Fedyk, A., He, A. & Hodson, J. (2024). “Artificial Intelligence, Firm Growth, and Product Innovation.” Journal of Financial Economics, 151, 103745.
[3] Gofman, M. & Jin, Z. (2024). “Artificial Intelligence, Education, and Entrepreneurship.” Journal of Finance, 79(1), 631–667.
[4] Brynjolfsson, E., Rock, D. & Syverson, C. (2021). “The Productivity J-Curve: How Intangibles Complement General Purpose Technologies.” American Economic Journal: Macroeconomics, 13(1), 333–372.
[5] Filippucci, F., Gal, P. & Schief, M. (2024). “Miracle or Myth? Assessing the Macroeconomic Productivity Gains from Artificial Intelligence.” OECD Artificial Intelligence Papers, No. 29.
[6] Misch, F., Park, B., Pizzinelli, C. & Sher, G. (2025). “Artificial Intelligence and Productivity in Europe.” IMF Working Paper WP/25/67.
[7] Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended.
Dr Panayiotis C. Andreou and Dr Costas Tziouvas (Cyprus University of Technology)
Amazon Web Services (AWS) appreciates the opportunity to comment on the draft Cyprus National AI Strategy 2032. AWS welcomes the Strategy’s ambitious, adoption-led, and execution-focused approach. Its emphasis on cloud-first adoption, responsible public-sector use cases, SME participation, applied skills, trusted public-private and international partnerships, interoperability, portability, vendor diversity, risk-based governance, and regulatory sandboxes provides a strong foundation for responsible AI adoption, innovation, competitiveness, and broad-based productivity growth.
The recommendations below focus on implementation choices that can help translate this ambition into sustained deployment while preserving customer choice, legal certainty, open and fair competition, and consistency with the harmonized European framework. AWS understands that the consultation document is a strategic policy framework rather than implementing legislation. Measures expressed in mandatory terms should therefore be clarified as policy proposals. Any future binding obligations should be established through an appropriate legal basis, with defined scope, proportionality, procedural safeguards, and consultation with affected stakeholders.
1. Private-sector obligations and conditional access
Article/paragraph reference: Section 3.5, Priority Sectors (pp. 29-30); Annex C, introductory provisions for the Regulated Private Sector and Private Companies/Organisations (p. 60).
Comment/recommendation: Clarify which provisions are non-binding policy guidance and which may be proposed for future legal effect. The Strategy should clarify that disclosing an enterprise AI strategy or acceptable-use policy will not constitute an additional condition for granting or renewing an operating license beyond requirements established under applicable sectoral law. Any eligibility conditions for public funding, national compute, or datasets should be transparent, objectively justified, risk-based, proportionate, and non-discriminatory. They should be limited to information necessary for participation in the relevant resource or program and should include robust protection for trade secrets, confidential business information, and security-sensitive information. Any future binding requirements should have a clear legal basis, use terms aligned with the EU AI Act and applicable sectoral law, distinguish the responsibilities of different actors in the AI value chain, and be developed in consultation with the competent regulators and affected stakeholders.
Rationale: The Strategy states that industry adoption is not mandatory, but it also provides that every sizable organization must formalize an AI adoption plan. Annex C would give Institutional AI Strategies in regulated sectors the same legal weight as risk-management frameworks and would require certain private enterprises to share AI policies to obtain or renew operating licenses or access public AI resources. Key terms, including “sizable organization,” “critical and high-risk systems,” “strategic sectors,” and “basic compliance,” are not defined. This creates legal uncertainty and may duplicate obligations under the EU AI Act or existing sectoral supervision. Conditioning the right to operate on disclosure of a forward-looking AI strategy would be disproportionate to the policy objective and could discourage responsible adoption. Proportionate program-specific conditions can support accountability without creating a broader market-access requirement.
2. EU AI Act alignment and a complementary national compliance proposition
Article/paragraph reference: Section 3.9.6, AI Social Contract Principles (pp. 43-44); Section 4.3, AI Governance Enablers (pp. 49-50); Section 5, Immediate Steps, item 4 (p. 51); Annex A (pp. 53-55); Annex C, Government and Public Sector (p. 63) and Legal Services (pp. 74-76).
Comment/recommendation: Implement the Strategy through risk-based and proportionate measures that remain fully aligned with the EU AI Act and preserve Single Market consistency. Registration in the EU database should apply only where the AI Act requires it. Any national registry should have a clearly defined purpose, avoid duplicative reporting, collect only necessary information, and protect confidential business and security-sensitive information. A general annual audit requirement should not extend beyond applicable EU or sectoral obligations. The National AI Compliance Framework should operate as a voluntary, outcome-based, technology-neutral, and interoperable support framework. Regulatory sandboxes and related assurance services should remain voluntary and should support, not replace or add to, the AI Act conformity-assessment framework. References to “foundation models” should be aligned with the AI Act term “general-purpose AI models.” Any national pre-certification service for such models should not become an additional condition for offering or deploying AI products and services, participating in public procurement, or accessing the Cyprus market. The Strategy should also distinguish the AI Act’s general August 2, 2026 application date from the amended application dates established by Regulation (EU) 2026/1744 (Digital Omnibus on AI) for Chapter III, Sections 1-3: December 2, 2027 for systems classified as high-risk under Article 6(2) and Annex III, and August 2, 2028 for systems classified as high-risk under Article 6(1) and Annex I.
Rationale: Cyprus’s ambition to become a compliance and testing hub can help innovators and SMEs if it provides practical, voluntary support. Universal registration, annual national audits, or pre-certification requirements would instead create a Cyprus-specific layer on top of harmonized EU rules, increasing cost, complexity, and uncertainty for organizations operating across the Single Market. The AI Act uses targeted registration and conformity-assessment obligations. General-purpose AI models are governed through a distinct EU-level regime, supported by the voluntary GPAI Code of Practice and supervision by the AI Office. National implementation should reinforce those common EU routes and avoid creating parallel market-access conditions. The extended application timeline for high-risk AI systems creates a preparation window that Cyprus can use to strengthen compliance readiness, expand its capacity to operate regulatory sandboxes, and develop assurance expertise, helping position the country as an early-mover jurisdiction for responsible AI deployment.
3. Digital sovereignty, infrastructure, procurement, and incentives
Article/paragraph reference: Section 1.1, The Vision (pp. 1-2); Section 3.3.1, Government Innovation Hub (pp. 25-26); Section 3.3.2, Controls (p. 27); Section 3.7, Infrastructure, Compute and Digital Sovereignty (pp. 38-39); Section 4.2.1, AI Infrastructure Enablers (p. 49); Section 5, Immediate Steps, items 2-4 (pp. 50-51).
Comment/recommendation: Retain and strengthen the Strategy’s recognition that sovereignty can be achieved through trusted partnerships, interoperability, portability, vendor diversity, and European integration. Interoperability and portability requirements should be proportionate to the relevant service layer and workload and should focus on outcomes such as commonly used data formats, documented interfaces, and practical data and workload migration capabilities. They should not prescribe specific orchestration architectures, internal implementation methods, or technical equivalence across distinct services. Operationalize sovereignty as customer agency and control, including the ability to choose and switch providers and to apply verifiable, auditable technical and operational controls over who can access data, where data is stored, how it is encrypted, and how services remain resilient. Sovereignty requirements should not be based on provider nationality, country of origin, mandatory localization, prescribed architectures, or ownership tests. Public procurement, grants, and incentive programs should remain open, competitive, non-discriminatory, outcome-based, and technology-neutral. Solutions should be assessed against objective workload requirements, including security, functionality, performance, resilience, sustainability, and total cost of ownership. National compute should complement broad and portable access to commercial cloud and AI services, enterprise applications, managed tooling, and European infrastructure. Industrial policy should support economy-wide AI diffusion by combining demand-side measures, including outcome-based public procurement, with well-designed incentives and access to finance for adopters. Support should enable firms, particularly SMEs, to invest in the full set of capabilities required for adoption, including eligible consumption-based cloud services, applications, implementation, skills, and organizational change, without favoring infrastructure ownership or capital expenditure where different delivery models meet objective program requirements. Qualification of delivery and implementation partners should use transparent, objective, proportionate, and non-discriminatory criteria open to qualified local and international providers and partners. RISC-V initiatives can advance Cyprus’s research and innovation ambitions. Public procurement should nevertheless remain outcome-based and technology-neutral and should not prescribe hardware origin, a specific architecture, or a particular technical solution.
Rationale: Access to compute is necessary but not sufficient for economy-wide AI adoption. Most firms, particularly SMEs, will adopt AI through commercially available applications, managed tooling, enterprise software, and implementation services rather than by interacting directly with raw GPU infrastructure or developing models in-house. A policy that concentrates support on infrastructure ownership or capital acquisition can underinvest in the application, tooling, organizational, and skills layers that enable production deployment. Empirical research by DeStefano, Johnstone, Kneller, and Timmis found that capital incentives favoring hardware could slow the diffusion of cloud, big data, and AI, with particularly pronounced effects for SMEs. National infrastructure and research can strengthen resilience and domestic capability, but they should expand the range of trusted options available to users rather than displace commercial or European capabilities.
4. Governance, industry engagement, and institutional coordination
Article/paragraph reference: Section 3.3, Governance and Controls, including Section 3.3.1 (pp. 21-24); Annex A, EU AI Act (p. 53); Annex C, Government and Public Sector (p. 63).
Comment/recommendation: AWS welcomes the Strategy’s emphasis on multi-stakeholder engagement, including its recognition of the National AI Taskforce as an independent advisory body, and supports the establishment of an Industry Advisory Board as a standing, non-binding channel for structured public-private dialogue. Broad and balanced representation across technology providers of different sizes, local innovators, SMEs, and businesses from priority sectors can provide practical implementation expertise, identify adoption barriers early, and help keep delivery responsive to technological and market developments. The Board should operate transparently and complement, rather than replace, wider stakeholder consultation and the statutory responsibilities of public authorities. More broadly, Cyprus should publish a clear and accessible allocation of policy, advisory, enablement, platform-operation, supervisory, and enforcement responsibilities across the proposed bodies. The framework should define decision rights, statutory powers, accountability, coordination procedures, conflict-resolution and escalation mechanisms, and predictable decision timelines. Implementation should preserve the independent exercise of the statutory powers of authorities designated under the EU AI Act, data-protection law, and applicable sectoral legislation. Regulated entities should have a clear point of contact and protection against duplicative information requests or conflicting guidance.
Rationale: The Strategy’s distributed model can bring valuable technical, legal, sectoral, and ethical expertise into decision-making. An Industry Advisory Board would complement the proposed public governance bodies with direct feedback from businesses that develop, deploy, and use AI. It can help translate strategic ambition into scalable implementation and allow practical barriers to be identified before they become entrenched. Clear allocation and coordination of institutional responsibilities would further strengthen the model. The Strategy names the Communications Commissioner and the Commissioner for Personal Data Protection as competent authorities without fully explaining their relationship with the National AI Authority and other proposed bodies. Greater clarity can reduce multiple supervisory interfaces, duplicative requests, and inconsistent guidance while preserving effective national coordination and respecting the statutory responsibilities of the relevant authorities.
5. Adoption delivery, SME enablement, workforce capability, and transition
Article/paragraph reference: Sections 3.5 and 3.6 (pp. 29-38); Sections 4.1-4.4 (pp. 47-50); Section 5 (pp. 50-52); Section 3.11, Measuring Impact and National KPIs (pp. 44-45); Annex C, Education and Human Capital Development (pp. 77-81).
Comment/recommendation: Operationalize the Strategy’s adoption initiatives through a clear and accessible firm-level pathway, particularly for SMEs. This should include sector-specific adoption roadmaps, practical support to identify viable use cases, access to commercially available AI applications and managed tooling, a diverse pool of qualified implementation partners, workflow-redesign and change-management support, and mechanisms for scaling proven deployments. Public-sector AI adoption should also serve as a demand-side catalyst. Open, competitive, and outcome-based procurement, combined with responsible and measurable deployments, can improve public services, demonstrate tangible benefits to citizens, create reference use cases, build public trust, and help strengthen Cyprus’s market for AI applications and implementation services. Where appropriate, contracting authorities should consider dividing flagship AI initiatives into proportionately sized lots that enable specialist firms of different sizes, including Cypriot SMEs and local integrators, to compete for suitable workstreams while preserving clear accountability, security, interoperability, and end-to-end delivery. Singapore’s SMEs Go Digital program, including sector-specific guidance and hands-on advisory support, provides a useful model. Workforce policy should take a full-stack approach covering innovators, facilitators, and users. It should pay particular attention to data architects, systems integrators, cloud engineers, sector specialists, middle managers, governance and assurance professionals, trainers, and change leaders. Progress should be measured not only through training participation and talent totals, but also through production deployments, SME participation, time from pilot to scale, workforce adoption, and measurable productivity gains. Workforce-related conditions attached to public funding should remain proportionate, outcomes-based, and consistent with applicable employment law. References to avoiding “headcount arbitrage” should not become general restrictions on legitimate business organization. At the same time, workers whose tasks or roles change should have access to modular retraining, career-transition assistance, active labor-market programs, and appropriate social dialogue.
Rationale: The Strategy provides strong foundations through ApplyAI, FutureAI CY, AI Officers, the AI Industrial Centre of Excellence, the National AI Skills Observatory, and stackable microcredentials. The remaining challenge is the end-to-end pathway through which firms move from awareness and experimentation to production deployment and measurable gains. Public-sector leadership can help activate this pathway. Unlocking Europe’s AI Potential 2026, research conducted by Strand Partners for AWS, found that 68% of businesses said they were most likely to increase their AI adoption when the public sector leads. The report also identifies streamlined, open, and competitive public procurement as a means of creating early demand and real-world validation for innovators. For Cyprus, these findings support using responsible public-sector adoption to build trust, stimulate market demand, and strengthen the AI ecosystem. Infrastructure, tools, and training do not generate impact automatically. Businesses also need implementation capacity, domain knowledge, management support, workflow redesign, and change leadership. The AI Labor Stack framework describes these facilitator roles as the connective layer between technical innovation and productive use. Building this layer, while supporting inclusive workforce transitions, will help Cyprus translate its adoption targets into broad-based and resilient productivity growth.
6. Human oversight, transparency, and explanations
Article/paragraph reference: Section 1.1, Fundamental Principles (pp. 1-2); Section 3.1.2, Design Principles (p. 19); Sections 3.9.2-3.9.6 (pp. 42-44); Annex A, Human-centred values and Transparency and explainability (pp. 54-55).
Comment/recommendation: Retain meaningful transparency, contestability, and human oversight, but align each requirement with the risk, autonomy, context of use, and role of each actor in the AI value chain. Avoid universal human-in-the-loop or model-level explainability requirements. For systems that affect rights or access to essential services, safeguards should include clear accountability, appropriate human review or escalation, and understandable information about the role of AI in the decision. The Strategy should align its references to a right to explainability with Article 86 of the EU AI Act, which concerns explanations of the role of a specified high-risk AI system and the main elements of certain individual decisions. It does not establish a general right to disclosure of how an underlying model functions. Transparency obligations should protect intellectual property, trade secrets, confidential business information, and security-sensitive information.
Rationale: Risk-appropriate human oversight and meaningful explanations support trust and accountability. A universal human-in-the-loop requirement, however, would not reflect the AI Act’s differentiated framework and may be unnecessary or impractical for low-risk and assistive uses. Similarly, requiring access to model internals may not produce a useful explanation for an affected person and could expose proprietary or security-sensitive information. Focusing on the system’s role, the relevant decision factors, available review mechanisms, and the responsibilities of the deployer provides more useful protection while preserving innovation and security.
7. Copyright, AI-generated works, and AIREG
Article/paragraph reference: Annex C, Legal Services, Implementation and flagship programs (pp. 74-76).
Comment/recommendation: Clarify the scope, purpose, governance, disclosure requirements, and intended legal effect of AIREG, including the definition of an “AI asset.” Any registry should be voluntary, technology-neutral, and evidentiary. It should not purport to create an EU-wide presumption of ownership or alter applicable rules on authorship, ownership, exceptions, or enforcement without an appropriate legal basis. Registration should not require disclosure of model weights, training data, source code, trade secrets, confidential business information, or security-sensitive information. The use of blockchain should not be prescribed where other technologies can meet the same objective.
Rationale: A registry can provide a timestamped record of a claim or support evidence management, but it cannot by itself establish authorship, ownership, validity, or enforceability across the European Union. Prescribing a specific technology or attaching an overly broad legal presumption could create uncertainty and conflict with existing national and EU intellectual-property frameworks. A voluntary, narrowly scoped approach can support innovators without creating a new mandatory disclosure or market-access mechanism.
8. AI-assisted judicial administration and adjudication
Article/paragraph reference: Annex C, Legal Services, Implementation and flagship programs (pp. 74-76).
Comment/recommendation: Support appropriate administrative applications, such as transcription, subject to accuracy, security, privacy, and data-protection safeguards. Reframe the proposed “AI judge capability” as AI-assisted judicial decision support. AI should not determine or issue judicial decisions; a judge should retain decisional authority, responsibility, and accountability. Any system materially assisting adjudication should be assessed under the applicable EU AI Act high-risk framework and should include safeguards for due process, data quality, auditability, transparency, contestability, human review, cybersecurity, and operational resilience. The framework should also distinguish purely ancillary administrative tools from systems used to research or interpret facts or law or to apply the law to a concrete case.
Rationale: Judicial decisions can significantly affect fundamental rights, even where the financial value is low or facts are described as uncontested. Errors, changing circumstances, procedural issues, or power imbalances may still require judicial judgment and an effective route to challenge. AI can improve court administration and help judges work more efficiently, but final legal authority and accountability should remain with the judiciary. This distinction is consistent with the Strategy’s broader commitment that technology should augment rather than replace professional judgment.
ΝΑΤΙΟNAL AI STRATEGY COMMENTING
31.08.2026
Strategy reference: Section 1.1, 1.4.3-1.4.10; and cross-cutting references to ‘European standards’.
Comment type: General / technical
CYS comment: The Strategy refers broadly to European and international standards but does not define the categories concerned, their different legal effects, or how standards will support implementation across the Strategy. The expression ‘European standards’ may be interpreted differently by ministries, authorities and market actors. Standardisation should be expressly integrated across the objectives in Sections 1.4.3-1.4.10 rather than confined to isolated references.
Proposed text for insertion or replacement Standardisation as implementation infrastructure. Cyprus shall use voluntary European, harmonised, International and National standards, together with open specifications, as practical instruments for AI governance, design, procurement, testing, assurance, deployment, monitoring, resilience and interoperability. For the purposes of this Strategy, “European standards” means standards adopted by CEN, CENELEC or ETSI under Regulation (EU) No 1025/2012; “harmonised standards” means European standards adopted in response to a Commission standardisation request in support of Union harmonisation legislation; “international standards” means those adopted by ISO, IEC or ITU; “national standards” means those adopted by the Cyprus Organisation for Standardisation (CYS); and “open specifications” means publicly available technical specifications developed through an open and consensus-based process by a body other than a recognised standardisation organisation. Only a harmonised standard whose reference has been cited in the Official Journal of the European Union may confer a presumption of conformity, and only for the requirements and conditions covered by that citation, in accordance with Article 40 of Regulation (EU) 2024/1689. Where harmonised standards are not available or are insufficient, common specifications adopted under Article 41 of that Regulation may confer an equivalent presumption. Other standards and specifications may support good practice and global interoperability but do not in themselves confer that effect.
CY-02. Replace Section 1.4.10 with an international cooperation, standardisation and EU-alignment commitment
Strategy reference: Section 1.4.10, International Cooperation and EU Alignment.
Comment type: General / policy
CYS comment: The current provision lists EU legislation and programmes but does not identify formal AI standardisation, participation routes, or the connection between the AI Act, international interoperability and related digital legislation.
Proposed text for insertion or replacement – International Cooperation, Standardisation and EU Alignment
The Strategy shall:
(a) implement Regulation (EU) 2024/1689 (the AI Act) and prepare for the application of the European harmonised standards being developed by CEN-CENELEC JTC 21 in response to the Commission’s standardisation request;
(b) align, where appropriate, with the work of ISO/IEC JTC 1/SC 42 and with relevant ITU-T, ETSI and sector-specific standards, in order to support global interoperability and international trade;
(c) support the active participation of Cypriot experts — from government, industry, SMEs, academia, research, professional bodies, workers, consumers and civil society — in CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42, ETSI and other competent technical bodies, through CYS and the national mirror committee system;
(d) use standardisation as a strategic policy instrument for innovation, interoperability, market access, procurement and conformity readiness throughout the AI lifecycle;
(e) ensure coherence between AI implementation and Regulation (EU) 2016/679 (GDPR), Directive (EU) 2022/2555 (NIS2), Regulation (EU) 2019/881 (Cybersecurity Act), Regulation (EU) 2022/2554 (DORA), Regulation (EU) 2024/2847 (Cyber Resilience Act), Regulation (EU) 2023/2854 (Data Act), Regulation (EU) 2022/868 (Data Governance Act), Regulation (EU) 2024/1183 (European Digital Identity Framework) and other applicable legislation, and monitor pending instruments, including the proposed revision of the Cybersecurity Act and the proposed amendments to NIS2, as they are adopted;
(f) strengthen participation in Digital Europe, Horizon Europe, EuroHPC, AI Factories, European Digital Innovation Hubs, Testing and Experimentation Facilities and initiatives of the European AI Office; and
(g) foster bilateral and multilateral cooperation for knowledge exchange, responsible innovation and globally compatible governance.
CY-03. Use European and international standards to establish Cyprus as a trusted AI jurisdiction
Strategy reference: Section 2.5.1, Objective 1: Establish Cyprus as a trusted jurisdiction for AI.
Comment type: General / policy
CYS comment: The objective relies on governance, regulatory clarity and assurance but does not explain how organisations will demonstrate these qualities in a consistent and internationally recognisable way.
Requested amendment: Extend Objective 1 to identify recognised European and international standards as part of Cyprus’s trust and investment proposition
Proposed text for insertion or replacement – Cyprus will position itself as a jurisdiction where AI is developed and deployed in a predictable, transparent, accountable and internationally interoperable manner. Trust will be built through strong governance, regulatory clarity, full alignment with European law, and the risk-based use of applicable European harmonised standards, other European standards adopted by CEN, CENELEC or ETSI, and internationally recognised standards from ISO/IEC, ITU-T and relevant sector bodies. The Cyprus Organisation for Standardisation (CYS), as the national standardisation body and in cooperation with the National AI Authority, will coordinate national participation in standardisation and the monitoring of relevant developments, so that Cypriot organisations can demonstrate recognised governance, risk-management, data-quality, security, lifecycle and assurance practices. Standards will be selected according to their legal role, system risk, sector and intended use, and do not replace compliance with applicable law.
CY-04. Integrate data-quality and data-governance standards
Strategy reference: Section 3.2, Data as a Strategic National Asset, and related sector data provisions.
Comment type: Technical
CYS comment: The Strategy correctly treats data quality, availability, interoperability and governance as prerequisites for trustworthy AI, but it does not establish a standards-based method for evaluating those qualities across the data lifecycle.
Requested amendment: Require cross-sector and sector-specific data standards profiles, measurable quality criteria and reusable evidence.
Proposed text for insertion or replacement – 3.2.6 Data Standards and Quality Assurance
Data quality and governance must be demonstrable rather than merely asserted. This Strategy therefore establishes a standards-based method for defining, evidencing and assuring data quality across the AI lifecycle, building on the interoperability commitments set out in Section 3.2.3.
The National AI Authority, in cooperation with the Cyprus Organisation for Standardisation (CYS) as the national standardisation body, together with data owners, competent authorities and sector stakeholders, will develop and maintain national data standards profiles. Each profile will specify, for each of the following dimensions, the applicable requirements or an express statement that none apply. Data quality dimensions will follow the data quality model and characteristics established in ISO/IEC 5259-2, selecting those relevant to the intended use, and for high-risk AI systems will address as a minimum the relevance, representativeness, completeness and freedom from errors required by Article 10 of Regulation (EU) 2024/1689, together with the balance and diversity characteristics relevant to bias examination. Governance dimensions will address terminology and shared semantics, metadata and documentation, provenance and traceability, access control, privacy and security, retention, and technical interoperability with the National Intelligent Digital API Fabric. Profiles select from and constrain the underlying standards; they do not modify or relax their requirements.
Profiles will be developed at two levels: a cross-sector baseline applicable to all public-sector data, and sector-specific profiles for the priority sectors identified in Section 3.5, reflecting established health, financial, geospatial, public-sector and maritime data standards.
For AI systems classified as high-risk under Regulation (EU) 2024/1689, profiles will be based on the European harmonised standards developed by CEN-CENELEC JTC 21 in support of Article 10 of that Regulation, in particular the standards on the quality and governance of datasets and on bias management, once those standards are published and their references cited in the Official Journal of the European Union.¹ For other systems, and for general data-quality modelling, profiles will draw on the ISO/IEC 5259 series developed by ISO/IEC JTC 1/SC 42, together with relevant ETSI and sector-specific standards. Conformity with a standard does not replace compliance with applicable law.
Each AI use case will identify the applicable data-quality criteria, test methods, thresholds, responsible owners and retained evidence across training, validation, testing, deployment and monitoring, proportionate to its risk classification. This evidence forms part of the documentation required at the control gates set out in Annex B, and is reusable across subsequent use cases drawing on the same datasets, reducing duplication of assurance effort.
The relevant standards are EN 18284 (Quality and governance of datasets) and EN 18283 (Bias management), currently in development by CEN-CENELEC JTC 21.
CY-05. Define CYS’s role in the governance architecture and prevent institutional overlap
Strategy reference: Section 3.3.1; Section 3.3.1.1, paragraph 1; line 1283; line 1357; Section 4.3, NAICF; Annex C Government and Public Sector, lines 3585-3586; and the governance diagram.
Comment type: General / governance
CYS comment: CYS and the national Standardization system are absent from the governance architecture, although the Strategy proposes common frameworks and standards, certification and compliance mechanisms, and a National AI Authority mandate to ‘provide standards’. The wording may create overlap with the statutory National Standardisation Body and with accreditation, conformity-assessment and regulatory functions.
Proposed text for insertion or replacement Relationship with the national standardisation system
The Cyprus Organization for Standardization (CYS) is the National Standardization Body of Cyprus, since January 1, 2005, and is responsible for all Standardization activities based on Law 156 (I)/2002.
Within the national standardisation system, CYS is responsible for the adoption and publication of standards at national level, for managing the National Standardisation System and establishing National Technical Standardisation Committees for all domains of the Industry. CYS actively participates in International and European Standardization as a full member of the International Standardization Organizations ISO and ITU, as well as the European Standardization Organizations CEN, CENELEC and ETSI. CYS represents Cyprus in European and International Technical Standardization Committees for Artificial Intelligence as an equal member, always aiming to safeguard the national interests.
CYS shall develop and maintain a National AI Standards Roadmap Report, published annually in coordination with the National AI Authority, mapping European and international standards to the objectives, implementation domains and priority use cases of this Strategy. The Roadmap Report shall be revised as necessary to reflect technological developments, new legislation and emerging standards, and shall inform the work of the National AI Authority in developing policy and governance frameworks and implementation guidance under Section 3.3.1.
The National AI Authority is responsible for policy, governance frameworks, regulatory guidance, implementation mechanisms and oversight within its legal mandate. It does not adopt, publish or develop standards. Where implementation of this Strategy requires the use of standards, the National AI Authority will identify the requirement and CYS will act within its statutory remit.
Competent authorities exercise statutory supervision and enforcement. The national accreditation body accredits conformity assessment bodies. Conformity assessment bodies perform assessment and certification under recognised schemes. National frameworks, registries and certification mechanisms established under this Strategy, including the National AI Compliance Framework, shall be designed to operate consistently with this division of functions and shall not duplicate accreditation or conformity assessment.
References in this Strategy to the National AI Authority “establishing common frameworks and standards” or “providing standards” shall be read as “developing policy and governance frameworks, implementation guidance and tools, in coordination with CYS where standards are implicated.”
CY-06. Recognise and fund national delegates and participation in standards development
Strategy reference: Section 3.12.2, Participation in European Initiatives; Section 3.3.1; Section 5 Immediate Steps; and Annex F.
Comment type: General / implementation
CYS comment: The Strategy does not recognise the work of CYS national delegates and experts or establish a mechanism for Cyprus to contribute to the European and international standards that will shape AI implementation and conformity assessment.
Requested amendment: Add national standards participation to the Strategy and provide an accountable participation mechanism.
Proposed text for insertion or replacement
Cyprus will participate actively in the development of European and international AI standards through CYS as the national standardisation body. Active participation ensures that national interests and priorities are reflected in the standards Cyprus will subsequently adopt.
At national level, CYS establishes and manages the National Mirror Committees, which bring together the national stakeholders concerned with a given field of standardisation, examine draft standards, form the national consensus position, and nominate the delegates and experts who represent Cyprus. This Strategy recognises the status of those delegates and experts and reinforces the existing subsidy scheme supporting their participation, extending it to the AI standardisation priorities identified under this Strategy.
At European and international level, delegates act on the basis of the national consensus positions so formed. The priority bodies are the European technical committee CEN-CENELEC JTC 21 on artificial intelligence, the international subcommittee ISO/IEC JTC 1/SC 42 on artificial intelligence, the European technical committee ETSI TC SAI on securing artificial intelligence, and relevant sector committees, with participation open to public authorities, industry, SMEs, academia, research organisations, professional bodies, workers, consumers and civil society.
CYS will coordinate national comments, delegate nominations, stakeholder consultation and periodic briefings. Participation priorities and expected outcomes will be set out in the National AI Standards Roadmap Report referred to in Section 3.3.1 and reviewed annually.
CY-07. Mandate a living National AI Standards Roadmap
Strategy reference: Sections 3.3, 3.11, 3.12.2 and 3.13; Section 5 Immediate Steps; and Annex F.
Comment type: General / implementation
CYS comment: The Strategy does not assign an owner, process, update cycle or implementation map for standards. A static list in the Strategy would also become obsolete as legislation, harmonised standards and international standards develop.
Requested amendment: Require a CYS-coordinated National AI Standards Roadmap within six months of the Strategy’s adoption and annual review thereafter.
Proposed text for insertion or replacement – The National AI Standards Roadmap Report referred to in Section 3.3.1 shall be first published within six months of the adoption of this Strategy and reviewed at least annually thereafter. It shall be prepared by CYS in cooperation with the National AI Authority.
The Roadmap Report shall:
(a) map applicable legal requirements and the relevant standards, controls, tests and evidence artefacts;
(b) identify each reference by category, distinguishing European harmonised standards, other European standards, international standards, national standards and open specifications as defined in Section 3.14;
(c) state the current development status and legal effect of each reference, including whether a harmonised standard has been cited in the Official Journal of the European Union;
(d) identify where sector, procurement, security and assurance profiles are required, for development in accordance with Section 3.2.6;
(e) identify gaps in the standards landscape and priorities for national participation; and
(f) be updated to reflect developments in legislation, standards and technology.
Competent authorities, regulators, the national accreditation body, public procurement authorities and the Digital Security Authority will provide the information necessary for the preparation of the Roadmap Report within their respective remits. Wider stakeholder input, including from academia, industry, SMEs, workers, consumers and civil society, is secured through the National Mirror Committees.
CY-08. Correct the treatment of AI management systems and AI risk management
Strategy reference: Section 3.13.1, Identification and Assessment of Risks; and Section 3.11.2.
Comment type: Technical
CYS comment: The Strategy describes ISO/IEC 42001 as a risk-management standard. ISO/IEC 42001 specifies requirements for an organisational AI management system; ISO/IEC 23894 is the dedicated international guidance on AI risk management. ISO/IEC 27001 addresses information-security management and should not be presented as establishing AI governance or complete legal compliance.
Requested amendment: Correct the standard references and require applicability to be determined by legal role, risk, sector and lifecycle stage.
Proposed text for insertion or replacement – A common methodology will be applied across implementing bodies, provided by ISO/IEC 23894 (Guidance on risk management for AI) and applied within the organisational governance framework of ISO/IEC 42001 (AI management system), supported by ISO/IEC 42005 for AI system impact assessment.
For AI systems classified as high-risk under Regulation (EU) 2024/1689, the European harmonised standards developed by CEN-CENELEC JTC 21 in response to the Commission’s standardisation request are the standards intended to support conformity assessment.¹ Once published and cited in the Official Journal of the European Union, they confer a presumption of conformity with the requirements they cover.
The applicability of any standard is determined by legal role, risk classification, sector and lifecycle stage, and is set out in the National AI Standards Roadmap Report. Implementation or certification of a management system does not by itself certify an AI system or establish compliance with all applicable legal requirements.
The relevant standard is EN 18228 (AI Risk Management), currently in development by CEN-CENELEC JTC 21.
CY-09. Strengthen operational resilience through continuous evidence and lifecycle assurance
Strategy reference: Section 3.13.2, Operational and Institutional Resilience; Sections 3.4 and 3.8.5; and Annex B.
Comment type: Technical / implementation
CYS comment: The Strategy lists redundancy, fail-safe mechanisms, human override and contingency procedures but does not require continuous operational evidence for learning or dynamic AI systems whose performance and risk may change after deployment.
Requested amendment: Add continuous monitoring, traceable evidence and standards-based lifecycle assurance, including consideration of ETSI TS 104 008 where applicable.
Proposed text for insertion or replacement: Operational resilience will be supported by documented service objectives, redundancy, fail-safe and fallback arrangements, human-oversight and override mechanisms, incident response, recovery, change control and post-market monitoring. For learning, adaptive or otherwise dynamic AI-enabled systems, assurance plans will define measurable requirements, monitoring metrics, evidence sources, thresholds, escalation rules and responsibilities throughout operation. Where appropriate, organisations should consider ETSI TS 104 008, Continuous Auditing-Based Conformity Assessment for AI-enabled systems, or successor standards as a methodology for continuous evidence gathering and conformity-status review. Use of continuous or automated assessment will not remove requirements for competent human judgement, independence, legal accountability or formal conformity assessment where required.
CY-10. Define the basis and institutional boundaries of AI audit and certification
Strategy reference: Section 3.9.6, proposed Cyprus AI Security & Certification Authority; Section 4.3, NAICF; and related annual-audit references.
Comment type: Legal / technical
CYS comment: The proposed annual audit does not identify the object of assessment, applicable standards, conformity-assessment scheme, assessor competence, accreditation basis, evidence, legal effect or relationship with AI Act conformity assessment. A separate national certification label could create duplication or misleading claims of EU recognition.
Requested amendment: Require recognised standards and schemes, define institutional roles and avoid creating an unsupported national AI-system certification regime.
Proposed text for insertion or replacement:
Any national AI audit, security or certification activity will be based on a published scheme identifying the object of assessment, the applicable legal requirements and standards, the scope of assessment, the evidence required, the frequency of assessment, requirements for independence and assessor competence, accreditation requirements, the decision process, surveillance arrangements, complaints and appeals procedures, conditions for suspension and withdrawal, and the legal effect of the outcome.
ISO/IEC 42001 certification applies to the organisation, not to its AI systems. It confirms that governance, roles, processes and controls for AI are in place and maintained. Each AI system remains subject to the requirements applicable to it, including conformity assessment where the system is classified as high-risk. Harmonised standards are the standards developed to support the requirements of Regulation (EU) 2024/1689. Conformity with a harmonised standard confers a presumption of conformity with the requirements it covers, provided its reference has been cited in the Official Journal of the European Union.
Within the national framework, CYS coordinates standards and national technical input. The national accreditation body accredits conformity assessment bodies. Conformity assessment bodies perform audits and certification under recognised schemes. Competent authorities retain supervision and enforcement.
The National AI Compliance Framework, and any national body performing audit or certification functions, will not represent their outputs as conferring EU-wide recognition or certification of an AI system unless that effect follows from applicable Union law and an authorised conformity assessment route.
CY-11. Reframe AIREG and the role of blockchain or DLT
Strategy reference: Legal Services pillar, including the AIREG proposal on strategy pages 34 and 75-76.
Comment type: Legal / technical
CYS comment: The Strategy confines DLT largely to AIREG while using language such as ‘immutable certification’ and a strong presumption of ownership that may overstate the legal and evidentiary effect of a blockchain entry.
Requested amendment: Require a technology-neutral feasibility and legal-design phase and define DLT as one possible evidence architecture rather than automatic proof or certification.
Proposed text for insertion or replacement: AIREG will be subject to legal, evidentiary, data-protection, cybersecurity, identity, interoperability, governance and cost-benefit assessment before implementation. The assessment will compare centralised and distributed architectures and identify the authoritative source, validation rules, governance, correction and appeal mechanisms, retention, cross-border recognition, liability, off-chain data and exit arrangements. Where DLT is justified, it may support tamper-evident timestamping, provenance, integrity and multi-party evidence records. A register entry will not by itself validate the truth or lawfulness of submitted information, create intellectual-property rights, establish authorship, certify AI Act compliance or displace the powers of courts, registries, regulators and competent authorities. The selected architecture will align with relevant CEN/CLC JTC 19 and ISO/TC 307 standards and with AI, cybersecurity, identity, privacy and digital-evidence requirements.
CY-12. Create a funded CYS-led AI standards uptake and conformity-readiness programme
Strategy reference: Section 3.3.1; Sections 3.6 and 4.2-4.4; Section 5 Immediate Steps; and Annex F.
Comment type: General / implementation
CYS comment: The Strategy proposes training and funding but does not assign responsibility for standards literacy, standards implementation, procurement support or national expert participation, and does not define measurable outputs.
Requested amendment: Establish a funded programme coordinated by CYS with the National AI Authority, Digital Security Authority and relevant sector bodies.
Proposed text for insertion or replacement – Standards uptake and conformity readiness. The National AI Standards Roadmap Report referred to in Section 3.3.1 will be accompanied by a national standards uptake programme, coordinated by CYS in cooperation with the National AI Authority. The programme will provide standards guidance and training for public sector and industry users, standards support for public procurement, reusable assurance and evidence templates aligned with the national data standards profiles, and support for national expert participation in European and international standardisation.
Standards uptake will be delivered through existing national training, SME support and innovation instruments established under Sections 3.6 and 4.4 of this Strategy, rather than through a separate delivery structure. Resourcing will be provided through existing mechanisms, including the national subsidy scheme for participation in standardisation.
CY-13. Add definitions and standards profiles for every priority sector
Strategy reference: Annex G Glossary and each Annex C priority-sector pillar.
Comment type: Technical / editorial
CYS comment: The glossary defines interoperability but not the principal standardisation and conformity-assessment concepts. Health is the clearest sector example, while other pillars lack an equivalent standards profile.
Requested amendment: Add legal and technical definitions and require an annually updated standards profile for every priority sector.
Proposed text for insertion or replacement – Annex G will define the following terms: standard; European standard; European harmonised standard; international standard; national standard; open specification; common specification; profile; conformity assessment; certification; accreditation; assurance; audit; validation; verification; and presumption of conformity. The definitions of the standards categories are those set out in Section 3.14.
Each priority sector pillar in Annex C will include a standards profile, maintained by CYS in cooperation with the competent sector regulator or authority and with input from industry, SMEs, professional bodies, academia, workers, consumers and users, and updated annually as part of the National AI Standards Roadmap Report.
Each profile will identify, for the sector concerned, the applicable cross-sector AI standards and domain-specific standards, organised according to the categories of the European standardisation request supporting Regulation (EU) 2024/1689:
(a) risk management for AI systems (Article 9);
(b) governance and quality of datasets used to build AI systems (Article 10);
(c) record keeping through built-in logging capabilities (Article 12);
(d) transparency and information to users of AI systems (Article 13);
(e) human oversight of AI systems (Article 14);
(f) accuracy specifications for AI systems (Article 15);
(g) robustness specifications for AI systems (Article 15);
(h) cybersecurity specifications for AI systems (Article 15);
(i) quality management systems for providers of AI systems, including post-market monitoring (Article 17);
(j) conformity assessment for AI systems (Article 43); and
(k) supporting standards, including terminology.
For each standard identified, the profile will record its designation and edition, its development status, its legal effect, its intended users, the criteria determining its applicability, and the owner responsible for updating the entry.
CY-14. Add standards and standardisation sources to Annex H
Strategy reference: Annex H Bibliography.
Comment type: Editorial / technical
CYS comment: The bibliography contains strategy and policy documents but no ISO/IEC, CEN-CENELEC or ETSI standards documents, despite the Strategy relying on standards for risk, security, governance and compliance.
Requested amendment: Add authoritative standards references and maintain the detailed list through the National AI Standards Roadmap.
Proposed text for insertion or replacement – Annex H will include, as sources for the standards relied on by this Strategy, CEN-CENELEC JTC 21, Artificial Intelligence — work programme and published deliverables, available at https://jtc21.eu, and ISO/IEC JTC 1/SC 42, Artificial Intelligence, available at https://www.iso.org/committee/6794475.html. Standards are available at national level through the Cyprus Organisation for Standardisation (CYS). Individual standards, their editions, status and legal effect are recorded in the National AI Standards Roadmap Report, which is maintained and updated as standards are published and revised.
CY-15. Recognise Cyprus standards leadership in distributed-systems engineering and forensics and evidence
Strategy reference: Section 3.12.2; Annex D Research and Innovation; Section 5 Immediate Steps; and relevant AI, DLT, finance, legal-services and public-sector pillars.
Comment type: General / strategic
CYS comment: The Strategy focuses on adopting technology and complying with external frameworks but does not identify credible routes through which Cyprus can contribute to the engineering foundations of emerging technologies. CYS identifies two distinct opportunities: a common methodology for describing distributed systems and the Cyprus-initiated ISO/TC 307/WG 10 work on forensics and evidence.
Requested amendment: Include both opportunities as separate but complementary national standards-leadership workstreams, subject to the governance of the competent committees.
Proposed text for insertion or replacement – Focus Area 7: Standards Engineering and Digital Evidence
This area translates national research capability into contributions to the engineering foundations of AI and distributed systems, positioning Cyprus as a contributor to international standards rather than solely an adopter of them. It links directly to the governance, assurance and conformity readiness priorities of the Strategy. Priorities include:
• A common, adaptable engineering methodology for describing distributed systems, covering stakeholders, components, data flows, governance, provenance and dependencies
• Forensics and digital evidence for distributed systems, including chain of custody, admissibility, and the limits of what tamper-evident records demonstrate⁹⁹
• Development of national use cases from justice, financial services, public accountability and AI incident assurance to support committee work
• Coordination of Cypriot expert participation, through CYS, in ISO/IEC JTC 1/SC 42, ISO/TC 307, ISO/TC 308, CEN-CENELEC JTC 21, CEN/CLC JTC 19 and relevant sector committees
Work in this area is subject to the governance and approval procedures of the competent committees, and no deliverable will be presented as an adopted standard before committee approval. Expected outcomes include contribution to international standards deliverables, exportable national expertise in digital evidence, and earlier national readiness for conformity assessment in AI and distributed systems.
ISO/TC 307/WG 10, Forensics and evidence, a working group of ISO/TC 307 Blockchain and distributed ledger technologies, established at the initiative of Cyprus. ISO/TC 307 holds liaisons with ISO/IEC JTC 1/SC 42 (Artificial intelligence), ISO/IEC JTC 1/SC 27 (Information security, cybersecurity and privacy protection)
CY-16. Recognise the role of CYS and national delegates in Annex A (DSA)
Strategy reference: Annex A, line 3058, sub-section “Harnessing the EU AI Act to Accelerate National Innovation”.
Comment type: General / policy
CYS comment: Throughout the Strategy there is no real mention of the work and role of CYS and its national delegates within the AI sector in Cyprus. There need to be mentions of the work done by CYS and the Cyprus delegation, and its importance regarding the future of AI in Cyprus.
Requested amendment: Under the sub-section “Harnessing the EU AI Act to Accelerate National Innovation”, add a new section titled “AI Standardisation”.
Proposed text for insertion or replacement:
AI Standardisation
Standardisation will help Cyprus develop a trusted, interoperable and competitive AI ecosystem. European and international standards provide practical, technical and organisational requirements for the quality, safety, security, interoperability and responsible development and use of AI systems.
The Cyprus Organisation for Standardisation (CYS), as the National Standardisation Body of Cyprus, plays a central role in managing the national standardisation system and in facilitating Cyprus’s participation in European and international standardisation. CYS represents Cyprus in the relevant European and international technical standardisation committees, facilitates the participation of national experts and stakeholders in standardisation activities, and adopts relevant European standards as Cyprus Standards.
CY-17. Recognise CYS’s role in monitoring EU-level developments and standards
Strategy reference: Annex A, paragraph 7, point 5, “Monitor EU-Level Developments and Standards”.
Comment type: General / policy
CYS comment: Throughout the Strategy there is no real mention of the work and role of CYS and its national delegates within the AI sector in Cyprus. There need to be mentions of the work done by CYS and the Cyprus delegation, and its importance regarding the future of AI in Cyprus.
Requested amendment: Add a sentence recognising the role of CYS in point 5 of the sub-section “Harnessing the EU AI Act to Accelerate National Innovation”.
Proposed text for insertion or replacement:
After “Monitor EU-Level Developments and Standards: To stay informed of evolving legislation, technical standards, and best practices, Cyprus will continue to maintain active engagement with EU institutions”, add:
CYS supports Cyprus’s engagement with relevant European standardisation activities through participation in Εuropean Standardization Technical Commitee CEN-CENELEC JTC 21 and through the dissemination and uptake of relevant standards at national level.
CY-18. Clarify the National AI Authority’s mandate in relation to standards
Strategy reference: Annex C, Government and Public Sector, “National AI Authority establishment” row.
Comment type: General / governance
CYS comment: The reference to the National AI Authority’s mandate to “provide standards” would benefit from further clarification. If the term refers to technical standards, harmonised standards, or standards supporting compliance with the AI Act, consideration should be given to the existing role of the Cyprus Organisation for Standardisation (CYS) as the National Standards Body and Cyprus’s representative within CEN, CENELEC, ISO and IEC. To avoid potential overlaps of responsibility, the Strategy may distinguish between standards development and adoption, which fall within the remit of CYS, and the development of AI policies, guidance, governance frameworks and implementation mechanisms, which fall within the remit of the National AI Authority.
Requested amendment: Amend the description of the National AI Authority’s mandate so that it does not extend to the development or adoption of standards.
Proposed text for insertion or replacement:
Replace “Authority with executive mandate to provide standards, enablement, compliance oversight, and platform operations” with:
Authority with executive mandate to provide governance frameworks and implementation guidance, enablement, compliance oversight, and platform operations, in cooperation with CYS as the National Standardisation Body where standards are implicated.
CY-19. Strengthen Cyprus’s international position through active contribution to standards development
Strategy reference: Section 2.3.4, Strengthening the International Position, paragraph beginning “The Strategy situates Cyprus…”.
Comment type: General
CYS comment: The Strategy appropriately identifies cooperation, interoperability and shared standards as important to Cyprus’s international AI position. However, the current wording principally describes Cyprus as a participant in European and international initiatives. Given the existing and developing CYS programme of work in AI standardisation, Cyprus has an opportunity to contribute actively to the development of international standards and methodologies, rather than primarily adopting standards developed elsewhere. This would provide a concrete means of supporting the Strategy’s stated ambition for Cyprus to become a trusted European AI hub and contributor to global norms.
Requested amendment: Add a bullet recognising Cyprus’s active contribution to international standards development.
Proposed text for insertion or replacement:
After the existing bullet “Contribute to the development of global norms for responsible AI”, add:
Contribute actively to the development of international AI standards, methodologies and guidance through CYS participation in European and international standardisation activities, with particular emphasis on areas where Cyprus can provide distinctive expertise and leadership.
CY-20. Recognise standards and methodological leadership in the Vision
Strategy reference: Section 2.4, The Vision: Where Cyprus Will Lead, key ideas.
Comment type: General
CYS comment: The Vision recognises that Cyprus should focus on areas where it can achieve leadership and differentiation rather than compete on scale. Standards development is an area in which a smaller Member State can exercise disproportionate influence through expertise, methodology and international collaboration. Explicitly recognising standards leadership would provide a realistic and distinctive route to European influence.
Requested amendment: Add a sixth key idea to the Vision.
Proposed text for insertion or replacement:
Add following the existing five key ideas:
6.Standards and methodological leadership: Cyprus will seek to contribute to the development of international standards, methodologies and governance approaches in strategically important areas of AI, using its participation in European and international standardisation to create influence beyond the scale of its domestic market.
CY-21. Extend the reuse and interoperability principle to use case description
Strategy reference: Section 3.1.2, Design Principles, “Reuse and interoperability”.
Comment type: Technical
CYS comment: The Strategy appropriately identifies common components and interoperable standards as a means of reducing duplication. The same principle could be extended to the description and analysis of AI use cases themselves. A common, structured methodology for describing use cases would improve consistency between institutions and sectors and enable systematic comparison and reuse. Inclusion of structured data-flow representations would additionally improve understanding of how data moves between actors, systems and governance boundaries.
Requested amendment: Amend the “Reuse and interoperability” design principle to include common methodologies for describing and analysing AI use cases.
Proposed text for insertion or replacement:
Reuse and interoperability – Shared platforms, common components, interoperable standards, and common methodologies for describing and analysing AI use cases will be prioritised to reduce duplication, improve comparability, and increase efficiency across organisations and sectors.
CY-22. Include structured data-flow representations in use case descriptions
Strategy reference: Section 3.2.3, Interoperability and Secure Data Sharing, paragraph beginning “AI requires…”.
Comment type: General
CYS comment: The Strategy identifies common data standards, shared definitions and interoperable architectures as strategic priorities. For AI governance, however, understanding the movement of data between actors, systems and organisational boundaries is also important for assessing privacy, security, accountability, provenance and risk. Structured representation of data flows within AI use cases would therefore complement the Strategy’s data-governance objectives and improve the accessibility and auditability of use case descriptions.
The ability to analyse different distributed systems, including AI, IoT and blockchain and distributed ledger technologies, using common metrics has the potential to provide an important governance dimension to the resulting engineering descriptions of apparently disparate systems. It also provides a basis for testing whether meaningful empirical comparisons can be made across different distributed system domains.
Requested amendment: Add a sentence requiring structured representation of data flows in use case descriptions.
Proposed text for insertion or replacement:
Add at the end of the first paragraph:
Use case descriptions should, where appropriate, include structured representations of relevant data flows, actors, system interactions and governance boundaries, supporting interoperability, risk assessment, accountability and auditability.
CY-23. Establish a common methodology for describing and assessing AI use cases
Strategy reference: Section 3.4.2, Use Case Driven Approach, and Section 4.4, AI Adoption Enablers.
Comment type: Technical
CYS comment: The Strategy places considerable emphasis on a use case driven approach and on reusable methodologies. This provides an opportunity to establish a common methodology for describing, assessing and comparing AI use cases across government and sectors. Such a methodology could be aligned with relevant international standards work and subsequently contribute to international standardisation. It would improve consistency, accessibility and comparability of use cases while supporting governance and reuse.
The ability to compare AI systems with other distributed technologies using a common descriptive and analytical framework could provide a powerful governance mechanism, benefiting the assessment and development of all the systems being compared. This is particularly relevant as AI increasingly converges with other distributed technologies and infrastructure, making cross-domain understanding and comparison increasingly important for governance, assurance and standards development.
Requested amendment: Require the development and maintenance of a common methodology for describing and assessing AI use cases.
Proposed text for insertion or replacement:
Add after the first paragraph of Section 3.4.2:
A common methodology for describing and assessing AI use cases will be developed and maintained for application across government. The methodology will support structured description of actors, objectives, data flows, system interactions, governance considerations, risks and expected outcomes, enabling consistent assessment, comparison and reuse across sectors.
CY-24. Support structured comparison of AI use cases in national evaluation
Strategy reference: Section 3.11, Measuring Impact and National KPIs; Section 3.11.2, National Key Performance Indicators.
Comment type: Technical
CYS comment: The Strategy identifies comparability and actionability as important characteristics of national KPIs. A common structured methodology for AI use cases would provide a complementary basis for comparing use cases themselves, both within and across sectors. This could support more systematic evidence-based assessment of AI adoption, including identification of recurring patterns, outcomes, risks and implementation approaches.
Requested amendment: Add a provision supporting structured comparison of AI use cases in national evaluation.
Proposed text for insertion or replacement:
Add after the KPI list:
Where appropriate, national evaluation will also support structured comparison of AI use cases using the common methodology referred to in Section 3.4.2, enabling evidence and lessons from individual deployments to be compared and reused across sectors.
CY-25. Define a common structure for use case description in Annex B
Strategy reference: Annex B, AI Use Case Lifecycle and Control Gates, Purpose of the Lifecycle Approach and Stage 1.
Comment type: Technical
CYS comment: The Annex establishes a common lifecycle for AI use cases and explicitly seeks consistency across institutions. The methodology would be strengthened by defining a common structure for the description of use cases themselves, in addition to the lifecycle and control gates. In particular, structured data-flow representations can make use cases more accessible to different stakeholder groups and provide a basis for systematic comparison of AI use cases across institutions and sectors. This would also support governance by making data movement, system interactions and relevant accountability boundaries explicit.
Requested amendment: Add a common structured methodology for the description of use cases.
Proposed text for insertion or replacement:
Add following the paragraph “The use case lifecycle provides a common structure…”:
Use cases will be described using the common structured methodology referred to in Section 3.4.2, which, where applicable, identifies the problem and objectives, stakeholders and roles, system interactions, data and data flows, governance and accountability boundaries, risks, controls, expected outcomes and relevant standards. The methodology supports comparison and reuse of use cases across institutions and sectors.
CY-26. Proportionate guidance for smaller organisations and standards-based AI procurement
Strategy reference: Section 3.4.1, Priority Areas for Government Adoption; Section 4.4, AI Adoption Enablers.
Comment type: General / implementation
CYS comment: Section 3.4.1 commits the government to establishing principles and prerequisites for AI-first procurement models by 2032, but does not identify what those principles and prerequisites will be. As the largest buyer of AI systems in Cyprus, what the state requires in tender documentation will shape supplier capability across the market. Separately, most Cypriot organisations will engage with Regulation (EU) 2024/1689 as deployers rather than providers, and the Regulation does not specify what level of documentation is sufficient for them. The Strategy does not address this gap.
Proposed text for insertion or replacement:
The principles and prerequisites for AI procurement will make use of European and international standards, applied according to their function. Technical requirements will be specified by reference to applicable standards, with equivalent means of demonstration permitted in accordance with public procurement law. Supplier capability will be assessed separately from the AI system being procured, and certification against a management system standard will not be treated as evidence of conformity of a system. Tender documentation will specify the documentation and artefacts to be transferred to the contracting authority, including the evidence a public body requires to meet its own obligations under Regulation (EU) 2024/1689, and the obligations applying during contract performance in relation to model update, monitoring and incident reporting. The applicable standards for each category of procurement will be identified in the National AI Standards Roadmap Report and in the relevant sector standards profiles. Requirements will be proportionate to the risk of the system and to the size of the supplier, so that participation by SMEs is not restricted.
Χαιρετίζουμε την ετοιμασία της Εθνικής Στρατηγικής Τεχνητής Νοημοσύνης (ΤΝ) και τη θέση της σε δημόσια διαβούλευση. Θεωρούμε ιδιαίτερα σημαντική τη σύνδεση της Στρατηγικής με το ευρωπαϊκό κανονιστικό πλαίσιο και ειδικότερα με τον Κανονισμό για την Τεχνητή Νοημοσύνη (AI Act). Οι Εθνικές Αρμόδιες Αρχές μπορούν να συμβάλουν όχι μόνο στην εφαρμογή και εποπτεία του πλαισίου αυτού, αλλά και στην παροχή κανονιστικής σαφήνειας και στην ενίσχυση της εμπιστοσύνης διευκολύνοντας έτσι την ασφαλή και υπεύθυνη αξιοποίηση της ΤΝ.
Τα σχόλια που ακολουθούν υποβάλλονται λαμβάνοντας υπόψη το σύνολο των αρμοδιοτήτων του Γραφείου μας, περιλαμβανομένων των αρμοδιοτήτων του στο πλαίσιο του AI Act, της κυβερνοασφάλειας και των ηλεκτρονικών επικοινωνιών:
1. Πλαίσιο διακυβέρνησης και National AI Authority
Στην ενότητα 3.3.1 η Στρατηγική προτείνει ένα ευρύ πλαίσιο διακυβέρνησης, το οποίο περιλαμβάνει διάφορα σώματα/δομές για την υποστήριξη και υλοποίησή της.
Η «National AI Authority» περιγράφεται ως φορέας στρατηγικού συντονισμού και υλοποίησης αλλά και ως “governance and control gatekeeper” με αρμοδιότητα μεταξύ άλλων, για την ανάπτυξη κοινών πλαισίων και προτύπων και τη διασφάλιση ευθυγράμμισης με τον Ευρωπαϊκό Κανονισμό και τους εθνικούς στόχους πολιτικής.
Θεωρούμε ότι θα ήταν χρήσιμο να αποσαφηνιστεί περαιτέρω ο ρόλος και οι αρμοδιότητες της National AI Authority καθώς και ο τρόπος αλληλεπίδρασής της με τις υφιστάμενες Εθνικές Αρμόδιες και Ρυθμιστικές Αρχές ιδιαίτερα σε θέματα που σχετίζονται με την εφαρμογή του AI Act. Παράλληλα προτείνεται να προστεθεί συγκεκριμένη αναφορά/παράγραφος στις υφιστάμενες εθνικές αρμόδιες αρχές και στις προβλεπόμενες αρμοδιότητές τους, ώστε να αποφεύγονται επικαλύψεις και να διασφαλίζεται η σαφής διάκριση μεταξύ στρατηγικού συντονισμού και πολιτικής και των εποπτικών ή ρυθμιστικών αρμοδιοτήτων των Εθνικών Αρμόδιων Αρχών.
2. National AI Compliance Framework (NAICF)
Η Στρατηγική προτείνει τη δημιουργία ενός «National AI Compliance Framework (NAICF)», ευθυγραμμισμένου με το AI Act και με αξιοποίηση του ISO 42001 και του AIGP. Σύμφωνα με το κείμενο, το NAICF θα καθορίζει “standardised compliance protocols for developers and deployers”, θα υποστηρίζει κεντρικό εθνικό μητρώο AI systems certified under EU rules και θα συντονίζεται με το Research and Innovation Foundation (RIF) και το Office of the Chief Scientist για compliance readiness και auditing innovation. Σε άλλο σημείο της Στρατηγικής αναφέρεται επίσης ότι το NAICF θα έχει ρόλο “support certification, auditing, and regulatory oversight”.
Η δημιουργία του National AI Compliance Framework (NAICF) μπορεί να αποτελέσει σημαντικό εργαλείο για την υποστήριξη της αγοράς, παρέχοντας πρακτική καθοδήγηση και κοινές μεθοδολογίες που θα διευκολύνουν developers και deployers στην κατανόηση και εφαρμογή των απαιτήσεων του AI Act.
Στο πλαίσιο αυτό θα ήταν χρήσιμο να αποσαφηνιστεί περαιτέρω ο χαρακτήρας και η λειτουργία του NAICF, ιδιαίτερα σε σχέση με τις αναφορές της Στρατηγικής σε “standardised compliance protocols” και σε υποστήριξη “certification, auditing and regulatory oversight”. Η αποσαφήνιση αυτή θα βοηθήσει ώστε να διακρίνονται σαφώς τα εργαλεία και οι μηχανισμοί υποστήριξης της αγοράς που θα παρέχονται μέσω του NAICF από τις ρυθμιστικές υποχρεώσεις και τις επίσημες διαδικασίες συμμόρφωσης που προβλέπονται από το AI Act (π.χ. διαδικασία conformity assessment που διενεργείται από conformity assessment body ή διαδικασίες και εξουσίες των Εθνικών Αρμόδιων Αρχών βάσει του άρθρου 74).
Σε σχέση με την πρόταση για δημιουργία κεντρικού εθνικού μητρώου AI systems certified under EU rules, θα ήταν χρήσιμο να διευκρινιστεί ο σκοπός και η προστιθέμενη αξία του μητρώου ώστε να αποφεύγεται η επικάλυψη με τα υφιστάμενα ενωσιακά εργαλεία και κυρίως η δημιουργία σύγχυσης ως προς τον επίσημο χαρακτήρα και τη νομική σημασία της εθνικής καταχώρισης. Θα μπορούσε να εξεταστεί ένα μητρώο με σαφώς προσδιορισμένο σκοπό, π.χ. ως χαρτογράφηση συστημάτων ΤΝ που δραστηριοποιούνται στην Κύπρο, χωρίς η καταχώριση να υποδηλώνει ή να συνεπάγεται επίσημη διαπίστωση συμμόρφωσης με το AI Act.
3. AI Industrial Centre of Excellence και AI Act compliance
Στον πυλώνα Financial Services and Financial Technology αναφέρεται ότι το AI Industrial Centre of Excellence θα λειτουργεί ως “sandbox of sandboxes” και σε συνεργασία με το CySEC Innovation Hub και το Regulatory Sandbox θα κάνει “validate models against EU AI Act requirements before commercial deployment”. Σε άλλο σημείο το Industrial Centre of Excellence περιγράφεται ως φορέας που θα παρέχει resources, development and engineering και governance guidance, με στόχο μεταξύ άλλων, την επιτάχυνση της προετοιμασίας για συμμόρφωση με το AI Act.
Θεωρούμε ότι θα ήταν χρήσιμο να αποσαφηνιστεί τι περιλαμβάνει στην πράξη η αναφορά σε “validation against EU AI Act requirements” και ποια είναι η σχέση αυτής της δραστηριότητας με το AI Regulatory Sandbox που προβλέπεται από το AI Act.
Επίσης στην ενότητα 3.8.5 προβλέπεται η δημιουργία National AI Testbeds για real-world experimentation and validation, τα οποία θα μπορούν να επεκτείνονται μέσω sectoral sandboxes. Παράλληλα η Στρατηγική αναγνωρίζει ότι regulatory sandbox mechanisms(σελ. 32) μπορούν να χρησιμοποιούνται όπου ενδείκνυται για ελεγχόμενο πειραματισμό.
Θεωρούμε ότι και σε αυτή την περίπτωση θα ήταν χρήσιμο να αποσαφηνιστεί περαιτέρω η διάκριση και η σχέση μεταξύ των διαφορετικών αυτών μηχανισμών και ειδικότερά, η θέση του AI Regulatory Sandbox που προβλέπεται από το AI Act στο ευρύτερο οικοσύστημα δοκιμών και καινοτομίας.
4. Control Framework – Incident Reporting
Στην ενότητα 3.3.2 προβλέπεται η καθιέρωση διαδικασιών για incident reporting, escalation και remediation.
Θα ήταν χρήσιμο να αποσαφηνιστεί η σχέση των διαδικασιών αυτών με τις υποχρεώσεις αναφοράς περιστατικών που προβλέπονται ήδη από το AI Act και άλλα εφαρμοστέα ευρωπαϊκά πλαίσια, ώστε να αποφεύγονται όπου είναι δυνατό παράλληλες διαδικασίες και πρόσθετο διοικητικό βάρος για τους επηρεαζόμενους φορείς. Η Στρατηγική θα πρέπει, ως εκ τούτου, να διατυπώνεται κατά τρόπο που να μην προδικάζει ή δημιουργεί de facto αρμοδιότητες για φορείς πέραν εκείνων που προβλέπονται από το εφαρμοστέο θεσμικό και νομοθετικό πλαίσιο.
Στο πλαίσιο αυτό θα μπορούσε να εξεταστεί η δυνατότητα ενός ενιαίου σημείου υποβολής αναφορών και διαβίβασής τους στις κατά περίπτωση αρμόδιες αρχές.
Για τα AI-related incidents που έχουν διάσταση κυβερνοασφάλειας, βλ. επίσης σχετικό σχόλιο στο σημείο 8 πιο κάτω.
5. Small and Medium-sized Enterprises and Small Mid-Cap Enterprises
Η Στρατηγική προβλέπει σειρά μέτρων για την υποστήριξη των SMEs. Δεδομένου ότι το αναθεωρημένο AI Act, μετά τις τροποποιήσεις του Digital Omnibus on AI αναγνωρίζει πλέον ρητά και τις small mid-cap enterprises (SMCs) σε σειρά μέτρων υποστήριξης της καινοτομίας και απλούστευσης(simplification), θα μπορούσε να εξεταστεί κατά πόσο ορισμένες από τις σχετικές δράσεις της Στρατηγικής θα ήταν σκόπιμο να καλύπτουν και τις SMCs όπου αυτό κρίνεται κατάλληλο.
6. Annex D – Focus Area 5: Next-Generation Wireless Telecommunications
Any deployment of AI-integrated network management, dynamic traffic routing, or network slicing (5G/6G) mentioned in the Strategy must operate in full compliance with Regulation (EU) 2015/2120 (Open Internet Regulation) and the relevant BEREC Guidelines. The application of AI for traffic optimization must not compromise the fundamental principle of net neutrality or lead to arbitrary traffic degradation.
7. Σχόλια στο Executive Summary
i. Σε σχέση με την αναφορά «Security and Resilience: AI systems are designed to be robust against misuse, failure, and cyber threats. Protection against adversarial AI attacks, establishing operational redundancy, and secure operational guardrails are key priorities»
Particular attention should be given to threats such as prompt injection, data poisoning, model poisoning, model manipulation, model inversion, model extraction and other adversarial machine learning attacks. Operational redundancy, continuous monitoring, secure operational guardrails and comprehensive incident response mechanisms should constitute key priorities.
ii. Σε σχέση με την αναφορά «Embed ethical governance, transparency, and trust in the AI systems through EU AI Act alignment and robust national safeguards.»
The explicit reference only to the EU AI Act not fully reflect the broader legal, regulatory and cybersecurity framework governing the development, deployment and operation of AI systems.
To enhance clarity, legal certainty and implementation consistency, it would be beneficial to explicitly refer to the legislative, regulatory and standards framework upon which the national strategy is based. ie NIS2 Directive etc
iii. Σε σχέση με την αναφορά «Transform public services through AI-enabled delivery, improving efficiency, accessibility and citizen experience while maintaining human oversight.»
the wording could be changed as follows:
“Transform public services through AI-enabled delivery, improving efficiency, accessibility and citizen experience while ensuring meaningful human oversight, intervention, accountability, control, review and final decision-making authority whenever required.”,
since limiting human involvement solely to oversight may not be sufficient, particularly in the context of high-risk or safety-critical AI systems.Human involvement should extend beyond passive supervision and should include the authority and responsibility to intervene, challenge, override, suspend or terminate the operation of AI systems whenever necessary.
iv. Σε σχέση με την αναφορά «Ensure secure, sovereign, and interoperable data and infrastructure foundations, and policies supporting resilience, security and strategic autonomy.»
Μπορεί να συμπληρωθεί με την αναφορά By adopting robust cybersecurity, resilience and digital sovereignty principles, including encryption, zero-trust architecture, secure data-sharing mechanisms, secure MLOps practices, model protection controls and continuous monitoring capabilities.
v. Σε σχέση με την αναφορά «Financial Services and Financial Technology: Anti Money Laundering (AML), compliance, intelligent insurance, AI-augmented CFO capabilities.»
it is suggested to define the Terrorist Financing, transaction monitoring, sanctions screening, fraud detection.
8. Infrastructure, Compute and Digital Sovereignty
Σε σχέση με την αναφορά «The National AI Infrastructure should serve as the shared computational and data backbone of Cyprus’s AI ecosystem, providing secure, scalable, and interoperable capabilities that support the full AI lifecycle, including model development, fine-tuning, inference, AI testing and validation, advanced scientific computing, and the deployment of AI solutions across priority sectors.»
Σημειώνουμε «The European Union, in its Action Plan on Cybersecurity and Artificial Intelligence (07 July 2026), has highlighted that most advanced frontier AI systems are currently being developed outside the European Union, creating significant strategic dependencies.
These dependencies may affect national resilience and cybersecurity.
In this context, it would be beneficial to emphasise the importance of strengthening sovereign national capabilities, promoting trusted partnerships and reducing critical external dependencies while maintaining alignment with European values, security requirements and strategic interests»
9. Responsible Deployment and Monitoring
Ιt would be beneficial to explicitly define the responsibilities of the relevant stakeholders in cases where an AI system causes operational disruption, compromises data integrity or becomes involved in a cybersecurity incident.
10. Εισήγηση:
Στα Priority Sectors στης Εθνικής Στρατηγικής ΤΝ, να περιλαμβάνονται όλες οι κατηγορίες(sectors) οντοτήτων που εμπίπτουν στο πεδίο εφαρμογής της NIS2(κυρίως των sectors του παραρτήματος Ι της οδηγίας), δεδομένου ότι η ασφαλής και ανθεκτική υιοθέτηση της ΤΝ στις οντότητες αυτές έχει ιδιαίτερη σημασία για τη λειτουργία κρίσιμων και σημαντικών υπηρεσιών.
Να σημειωθεί ότι οι οντότητες που εμπίπτουν στο σχετικό πλαίσιο οφείλουν να εφαρμόζουν κατάλληλα μέτρα για τη διασφάλιση της ασφάλειας, ανθεκτικότητας και ομαλής λειτουργίας δικτύων και πληροφοριακών τους συστημάτων, έναντι βλαβών, διαταραχών και κακόβουλων ενεργειών (Κ.Δ.Π. 389/2020). Ιδιαίτερα σημαντικό είναι ότι η σχετική απόφαση (Κ.Δ.Π. 389/2020) αναμένεται να τροποποιηθεί και να ενισχυθεί πολύ σύντομα (αναμένεται να εξαγγελθεί πολύ σύντομα δημόσια διαβούλευση) με επιπρόσθετες απαιτήσεις για την ασφάλεια των συστημάτων που σχετίζονται με τη Τεχνητή Νοημοσύνη. Επιπλέον, θα τροποποιηθεί η Απόφαση Κ.Δ.Π. 245/2024, με στόχο την ενίσχυση των Ελέγχων Ωριμότητας Κυβερνοασφάλειας μέσω της εισαγωγής πρόσθετων απαιτήσεων για την ασφάλεια των συστημάτων, συμπεριλαμβανομένων ειδικότερων απαιτήσεων που αφορούν την Τεχνητή Νοημοσύνη.
Θα ήταν επομένως χρήσιμο, η AI Strategy να συνδέει την υιοθέτηση της ΤΝ από τις οντότητες της Οδηγίας NIS2 με την κυβερνοασφάλεια, την κυβερνοανθεκτικότητα και τη λειτουργική συνέχεια, αλλά και να αναδεικνύει ότι η ΤΝ μπορεί να αποτελέσει εργαλείο ενίσχυσης της ανίχνευσης απειλών, της διαχείρισης κινδύνων, της αντιμετώπισης περιστατικών και γενικότερα της επιχειρησιακής ανθεκτικότητας.
11. Ποιος θα είναι υπεύθυνος για τη διακυβέρνηση και την εποπτεία της ΤΝ στην Κύπρο και πώς θα διαχωρίζονται στην πράξη οι αρμοδιότητες των αρμόδιων Αρχών, όπως της National AI Authority και της ΑΨΑ, ιδιαίτερα σε περίπτωση που ένα AI σύστημα προκαλέσει ή εμπλακεί σε περιστατικό κυβερνοασφάλειας;
Εισήγηση: Θα ήταν χρήσιμο η Στρατηγική να καθορίζει με μεγαλύτερη σαφήνεια τη σχέση και τα όρια αρμοδιότητας μεταξύ των αρμόδιων Αρχών, ώστε να αποφεύγονται επικαλύψεις ή κενά ευθύνης. Επιπλέον, θα ήταν σκόπιμο να προβλεφθεί ένας συντονισμένος μηχανισμός διαχείρισης AI-related cybersecurity incidents, ο οποίος θα αξιοποιεί το υφιστάμενο εθνικό πλαίσιο διαχείρισης περιστατικών κυβερνοασφάλειας.
Θα πρέπει να αποφεύγεται η δημιουργία ενός παράλληλου και απομονωμένου “AI incident management system” που θα λειτουργεί ανεξάρτητα από το υφιστάμενο cyber incident-response framework. Αντίθετα, τα AI-related incidents θα πρέπει να εντάσσονται στο υφιστάμενο πλαίσιο, με τις απαραίτητες πρόσθετες διαδικασίες για τους ειδικούς κινδύνους της ΤΝ.
12. Πώς θα διαχωρίζονται στην πράξη οι αρμοδιότητες του AI Officer από αυτές του CISO και του DPO; Ποιος θα έχει την κύρια ευθύνη όταν ένα AI σύστημα παραβιαστεί, δεχθεί κυβερνοεπίθεση, υποστεί αλλοίωση του μοντέλου ή των δεδομένων του, προκαλέσει διαρροή προσωπικών δεδομένων ή επηρεάσει τη λειτουργία μιας κρίσιμης υπηρεσίας;
Εισήγηση: Θα ήταν χρήσιμο να καθοριστούν με σαφήνεια οι ρόλοι και οι ευθύνες των εμπλεκόμενων λειτουργών, ώστε ο AI Officer να μην υποκαθιστά τον CISO ή τον DPO. Για AI-specific cybersecurity risks θα πρέπει να προβλέπεται υποχρεωτική συνεργασία AI Officer–CISO–DPO, ανάλογα με τη φύση του περιστατικού.
13. Ποιος θα έχει την εξουσία να αναστείλει ή να τερματίσει τη λειτουργία ενός AI συστήματος όταν διαπιστωθεί σοβαρός κίνδυνος για την κυβερνοασφάλεια, την προστασία δεδομένων, την ασφάλεια των πολιτών ή τη λειτουργία μιας κρίσιμης υπηρεσίας;
H Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη (ΤΝ) αναγνωρίζει ως τομέα προτεραιότητας την θεματική «Healthcare and Life Sciences» και περιλαμβάνει σημαντικές αναφορές σε κλινικές εφαρμογές, δεδομένα υγείας, διαλειτουργικότητα και εκπαίδευση. Ειδικότερα το θέμα της Δημόσιας Υγείας πιστεύουμε ότι θα μπορούσε να αναδειχθεί ρητά ως διακριτό πεδίο εφαρμογής της ΤΝ, καθώς έχει διαφορετικές ανάγκες από την κλινική φροντίδα και σημαντικές δυνατότητες αξιοποίησης μεγάλων και ετερογενών συνόλων δεδομένων σε πληθυσμιακό επίπεδο. Ιδιαίτερα από την οπτική της Δημόσιας Υγείας, θα μπορούσε να δοθεί μεγαλύτερη έμφαση στην επιδημιολογική επιτήρηση, την έγκαιρη ανίχνευση και εκτίμηση κινδύνου, την προσέγγιση “One Health”, την υποστήριξη της λήψης αποφάσεων και την αξιοποίηση δεδομένων σε επίπεδο πληθυσμού.
Προτείνεται να εξεταστούν προσθήκες, όπως:
1. “Artificial Intelligence for Public Health”
AI should be leveraged to strengthen public health surveillance, early detection and risk assessment, outbreak preparedness and response, and evidence-informed public health decision-making. Priority should be given to applications supporting the analysis of population-level, epidemiological, laboratory, environmental and other relevant data in a timely and integrated manner.
Specific use cases could include:
• Epidemiological surveillance and early detection of threats, through real-time data analysis, predictive analytics and early warning systems.
• One Health, through the integration of human health, animal health and environmental data, combined with GIS, environmental indicators, sensors and other surveillance systems.
• Support for evidence-informed decision-making, through predictive modelling, risk assessment and simulation tools to assess the potential impact of different public health interventions.
• Addressing misinformation and infodemics, particularly during public health emergencies.
• AI copilots for public health professionals, to support information retrieval and synthesis, data analysis, risk assessment and report generation, while maintaining appropriate human oversight.
• Smart and dynamic electronic forms and processes, which adapt to the information entered during inspections, assessments or investigations, reducing administrative burden and improving data quality.
2. Health-specific assessment of real-world impact and added value
The Strategy already recognises the importance of measuring the added value and impact of AI solutions in healthcare, including through measuring their contribution for wait time reduction, time to assessment, triage accuracy etc. It would nevertheless be useful to further specify a framework for public health which could include indicators such as: Positive predictive value and timeliness of alerts, forecast accuracy (Accuracy of predicted cases, hospitalisations, outbreaks, etc.), Outbreak impact (Reduction in outbreak size/duration where AI contributes to intervention), Health outcomes (Change in relevant morbidity, mortality or other outcomes), Workload reduction of Public Health personnel
3. Specialised AI Training for Healthcare and Public Health
“In addition to general AI literacy, specialised training should be developed for healthcare and public health professionals, covering the interpretation and appropriate use of AI outputs, model limitations, human oversight, data protection, bias, uncertainty and responsible use of AI in professional decision-making.”
Furthermore, in the Page 70 table (under the column “Expectation for 2026-2032” and for the strategic direction “Workforce upskilling and Socratic learning”), the expectation is Socratic AI-driven learning pathways and national capability building, aiming for 50% of the medical workforce trained in AI-enabled practices by 2032.
We suggest that capacity building should not be restricted to the medical workforce, but should extend to healthcare and public health professionals, recognising that the responsible and effective use of AI requires relevant competencies across the wider health and public health workforce.
4. Public Health Data, Interoperability and One Health
Under chapters “National frameworks and governance” (page 68) and “Implementation, evidence and compliance” (page 69) for Healthcare and Life Sciences we consider it important that the reference to health data be expanded to more explicitly include public health data.
The strategy could include:
“The development of AI in health should be supported by high-quality, interoperable and securely governed datasets, including clinical, public health, epidemiological, laboratory, and, where feasible environmental and animal health data, in line with a One Health approach.”
5. European Union document reference for AI in healthcare
Under chapter “International alignment” (page 68) for Healthcare and Life Sciences we suggest to add reference after the sentence “Cyprus will align implementation to WHO guidance and to European principles for trustworthy, human-centred AI in health.”
Reference to add:
European Commission: Directorate-General for Health and Food Safety, PwC, EEIG and Open Evidence, [Directorate-General for Health and Food Safety, PwC, EEIG, Open Evidence], Study on the deployment of AI in healthcare – Final report, Publications Office of the European Union, 2025, https://data.europa.eu/doi/10.2875/2169577
6. Applications of AI in public health (Oleribe et al., 2026 – table 1)
– Component: Assessment and Monitoring of Health; Predicted Roles: Use AI-powered “digital twins” of populations to simulate community health trends in real time; Expected Outcomes: Provide predictive analytics and preventive interventions enabling early detection of health risks and proactive interventions in populations, not just retrospective analysis.
– Component: Surveillance and Disease Control; Predicted Roles: Automated global surveillance networks integrating health, climate, and travel data; Expected Outcomes: Detect outbreaks before the first local report.
– Component: Health Promotion and Education; Predicted Roles: Immersive AI-driven personalized health coaching (VR-ECAs); Expected Outcomes: Adapt to cultural context and personal motivation dynamically.
– Component: Policy Development and Planning; Predicted Roles: Co-designing policy with AI by simulating economic, social, and health trade-offs instantly; Expected Outcomes: Predict long-term equity and economic impacts of policies in real time before implementation.
– Component: Health Protection and Regulation; Predicted Roles: Continuous AI-driven monitoring of supply chains, environmental systems, and workplaces; Expected Outcomes: Flag, report, and even correct hazards in real time.
– Component: Prevention Services; Predicted Roles: AI-guided precision prevention at the individual genetic and behavioral level; Expected Outcomes: Deliver fully personalized preventive care recommendations integrated into daily life.
– Component: Workforce Development; Predicted Roles: AI mentors and digital assistants to guide public health professionals through tasks; Expected Outcomes: Provide context-aware coaching during fieldwork or emergencies.
– Component: Community Engagement and Partnerships; Predicted Roles: AI-enabled “societal digital twins” that model disease outbreaks and how proposed interventions affect trust and equity. ; Expected Outcomes: Forecast community response to interventions before rollout, preventing mistrust and resistance.
– Component: Emergency Preparedness and Response; Predicted Roles: Fully autonomous logistics systems powered by AI and drones; Expected Outcomes: Support logistics systems in disasters and pre-position resources.
– Component: Evaluation and Research; Predicted Roles: AI-driven discovery engines that generate new hypotheses, design trials, and interpret results; Expected Outcomes: Conduct near real-time global meta-analyses and adapt interventions.
Bibliography:
Oleribe, O. O., Uzoaru, F., Tarfa, A., Olaniran, O. H., & Taylor-Robinson, S. D. (2026). Transforming Public Health Practice with Artificial Intelligence: A Framework-Driven Approach. Healthcare, 14(3), 385.
7. Γενικά σχόλια
Επίσης θεωρούμε ότι θα πρέπει να διευκρινιστεί ο τρόπος που θα είναι προσβάσιμα τα δεδομένα υγείας δεδομένου ότι απαιτείται συνεργασία μεταξύ διαφορετικών φορέων για την υγεία όπως Υπουργείο Υγείας, Οργανισμός Ασφάλισης Υγείας, Οργανισμός Κρατικών Υπηρεσιών Υγείας, Εθνική Αρχή Ηλεκτρονικής Υγείας, Εθνική Επιτροπή Βιοηθικής, Πανεπιστήμια, Ερευνητικά Κέντρα, κέντρα και εργαστήρια του εξωτερικού. Τα κλινικά δεδομένα θα πρέπει να είναι ανώνυμα και η Υπηρεσία μας θα πρέπει να έχει πρόσβαση σε αυτά για την περαιτέρω ανάλυση τους για την πρόληψη επιδημιών. Θεωρούμε σημαντικό ότι έχει ψηφιστεί ο περί Ηλεκτρονικής Υγείας Νόμος (59(Ι)/2019) ο οποίος προβλέπει τη δημιουργία ηλεκτρονικού φακέλου ασθενών στον οποίο θα περιέχονται το βασικό σύνολο δεδομένων υγείας των πολιτών. Βάσει του νόμου οι πολίτες διατηρούν το δικαίωμα για κλείδωμα ορισμένων δεδομένων υγείας τα οποία θα καθίστανται μη προσβάσιμα στον πάροχο υπηρεσιών υγείας. Επίσης ο πάροχος υπηρεσιών υγείας έχει πρόσβαση στον ηλεκτρονικό φάκελο υγείας μόνο εάν έχει εξουσιοδότηση από τον κάτοχο του ηλεκτρονικού φακέλου υγείας. Ως εκ τούτου εισηγούμαστε όπως γίνει αναφορά στους φορείς του τομέα της υγείας οι οποίοι δημιουργούν, καταχωρούν και επεξεργάζονται δεδομένα υγείας και να γίνεται αναφορά στην συγκατάθεση των πολιτών για την πρόσβαση των κρατικών υπηρεσιών δημόσιας υγείας για την ανώνυμη επεξεργασία τους.
Excellent and highly ambitious document! However, as a practicing IT specialist living and working in Cyprus, I would like to offer some pragmatic, technical adjustments to ensure this Strategy translates into successful, resilient, and highly impactful implementation.
To make this feedback easy to process for the working group, I have structured my suggestions into two logical categories: Horizontal Enablers and Sector-Specific Initiatives.
SECTION 1 – HORIZONTAL ENABLERS AND INFRASTRUCTURE
1.1 – G-Cloud Migration Timeline and Operational Stress-Testing [Reference: Strategy Document, Section 3.4 “AI Adoption Across Government” and Annex C “Government and Public Sector”, Page 62]
THE BLUEPRINT TIMELINE: The roadmap currently schedules G-Cloud architecture design completion for December 2026, with the migration of the first three pilot applications completed by March 2027.
THE OPERATIONAL CHALLENGE: A three-month window to migrate legacy government systems into a brand-new hybrid cloud environment is an extremely high-risk schedule that even agile private corporations rarely manage. A rushed sprint here poses severe architectural, operational, and security risks, including database integration failures, service downtime, and security vulnerabilities.
THE PROPOSED ADJUSTMENT: I suggest extending the pilot migration window from three to nine months, targeting September 2027. We should explicitly mandate that these first three applications must consist of non-critical, static datasets, such as public archival databases. This will allow the team to thoroughly stress-test G-Cloud’s security baselines and API Fabric before any high-risk personal or transactional databases are touched.
1.2 – AI Talent Target Segmentation (Class-A vs. Class-B) [Reference: Strategy Document, Section 3.6 “Talent, Skills and Workforce Transformation” and Annex C “Education and Human Capital Development – FutureAI CY”, Page 80]
THE KPI IN THE BLUEPRINT: The strategy aims to train 3,000 AI professionals by 2032 through stackable micro-credentials of 5 to 15 ECTS (approx. 150-450 hours of study).
THE OPERATIONAL CHALLENGE: Grouping high-end ML engineers, no-code creators, prompt writers, and basic public sector users under a single target of 3,000 professionals obscures the real engineering gap. A 150-hour course can train an administrator to use an AI interface, but it cannot produce an engineer capable of fine-tuning LLMs, managing security, or preventing model hallucinations in sensitive sovereign systems.
THE PROPOSED ADJUSTMENT: Subdivide the 3,000-talent target into two distinct tracks. Class A should cover core ML Engineers and AI Architects with a dedicated target of at least 15% (450+ specialists). Class B should cover No-code Creators and Business Users for the remainder of the training pool. Funding under the FutureAI CY program should prioritize rigorous, long-term engineering tracks to build the actual technical capacity required for digital sovereignty.
1.3 – “Zero-AI Baseline Test” to Prevent AI-Washing in Public Procurement [Reference: Strategy Document, Section 3.1.2 “Value-driven deployment”, Page 19 and Annex C, Page 61-62]
THE TARGET IN THE BLUEPRINT: Flagship public sector initiatives, such as the Digital Company 2.0 registration processes or the Skills and Labour Market Platform (NASO), are currently categorized under the core AI portfolio.
THE OPERATIONAL CHALLENGE: Aggregating job postings or automating basic business registrations are standard, deterministic database tasks. They are 100% solvable using secure relational databases, clean API integrations, and standard BI dashboards. Introducing probabilistic AI/LLMs where absolute, auditable accuracy is required introduces unnecessary risks of “hallucinations” and inflates software vendor quotes by 3x to 5x.
THE PROPOSED ADJUSTMENT: Integrate a mandatory Zero-AI Baseline Test within the ApplyAI project selection framework. Before approving AI-specific budgets, the National AI Authority must verify if the problem can be solved with high accuracy using classical automation, secure APIs, and relational databases. If yes, the project must be routed to standard digital transformation budgets (DMRID), preserving scarce AI-expert hours and GPU capacities for truly complex cognitive workloads (such as court transcription or medical image diagnostics).
SECTION 2 – SECTORAL INITIATIVES AND COMPLIANCE
2.1 – “Simplified Compliance Sandbox” for Startups and SMEs [Reference: Strategy Document, Section 3.11.2, Page 45 and Annex C “Government and Public Sector – Private Companies”, Page 60]
THE CONSTRAINT IN THE BLUEPRINT: To access state-subsidized grants, public datasets, or the national GPU cloud, private companies must share their ethical AI strategies and adhere to rigorous ISO 42001 and ISO 27001 standards.
THE OPERATIONAL CHALLENGE: Enforcing formal ISO compliance on early-stage local startups and SMEs (with under 1 million Euros in turnover) creates an insurmountable financial and bureaucratic barrier, stifling local tech entrepreneurship before it can take root.
THE PROPOSED ADJUSTMENT: Implement a Simplified Compliance Sandbox for startups and micro-SMEs. Instead of requiring external ISO certification on day one, the Ministry should provide free self-assessment templates, pre-audited compliance checklists, and automatic access to state-subsidized cloud resources. Formal ISO audits should only become mandatory once a startup matures or scales to high-risk public utility deployments.
2.2 – Establishing Physical IoT Foundations as a Prerequisite for “Destination Digital Twins” [Reference: Strategy Document, Annex C “Tourism and Hospitality”, Page 71-73]
THE TARGET IN THE BLUEPRINT: The strategy proposes developing complex “Destination Digital Twins” for tourism hubs (Limassol, Ayia Napa) to simulate climate impacts, heatwaves, and resource bottlenecks.
THE OPERATIONAL CHALLENGE: A true digital twin is a dynamic mathematical model that requires continuous, real-time data streams to be useful. On Cyprus, real-time data streams from existing local utility sensors remain highly fragmented, siloed across disparate municipalities, and lack unified standards and API integrations. Building predictive AI simulations without clean, real-time data pipelines is mathematically impossible and risks wasting budgets on static 3D maps that offer limited operational utility.
THE PROPOSED ADJUSTMENT: Postpone the modeling phase of “Digital Twins” to Phase 2 (post-2028). Reallocate Phase 1 budgets to co-fund the physical rollout of IoT sensor networks (smart water and electricity meters for hotels, traffic sensors) and to establish a Unified National IoT and Sensor Data Standard. Building this solid physical data foundation is a mandatory prerequisite before any intelligent predictive simulation can be successfully deployed.
The comments address three key dimensions of the Cyprus National AI Strategy 2032: (1) Governance, (2) Standardisation and Assurance, and (3) Technological and Security Sovereignty.
COMMENTS
1. National AI Authority: Considering the evolving AI landscape and the strategic, cross-sectoral and security-sensitive implications of AI, the effective implementation of the Strategy should consider the establishment or designation of a strong and appropriately independent National AI Authority. Such an Authority could serve as the central institutional mechanism for coordinating the implementation of the Cyprus National AI Strategy 2032, while ensuring alignment with the National Interest and the broader European regulatory and policy framework. Given the strategic and cross-sectoral nature of its mandate, the Authority should operate under an appropriate legal framework, with clearly defined responsibilities, powers, accountability mechanisms and interfaces with the existing competent authorities of the Republic. Its governance and modus operandi should reflect the strategic importance, security requirements and institutional safeguards associated with national-level authorities dealing with critical and security-sensitive matters, while avoiding duplication or interference with the statutory responsibilities of existing authorities. The National AI Authority could provide the central governance and coordination layer required to align national activities across the Research, Innovation, Development and Deployment (R&I&D&D) lifecycle of AI. Its overarching purpose should be to ensure that AI capabilities are researched, developed, acquired and deployed in a trusted, secure, resilient and sovereign manner, while protecting people, critical assets, strategic resources and national data; managing systemic risks, technological dependencies and supply-chain exposure; and safeguarding the sovereignty, resilience, security and long-term strategic interests of the Republic of Cyprus. Given the strategic significance and horizontal responsibilities, its institutional positioning should reflect a level of authority and access commensurate with other relevant national security and strategic authorities of the Republic.
(A) Proposed amendment to the Strategy: The establishment, designation, mandate and institutional positioning of a National AI Authority should be considered and discussed at the appropriate political and governmental level, taking into account the existing national institutional architecture and the applicable EU AI governance framework.
2. Standardisation and AI Assurance: Standardisation should constitute an integral component of the National AI Strategy and its implementation framework. This is critical for establishing the necessary levels of trust, interoperability, security, conformity and assurance across national AI activities. National participation in European and international AI standardisation is also strategically important for ensuring that Cyprus can both implement emerging standards and contribute to their development, particularly in areas related to trustworthy AI, cybersecurity, data, cloud/edge computing, AI assurance and conformity assessment. The contribution of the national standardisation bodies and relevant national experts of the Republic of Cyprus should therefore be explicitly incorporated into the governance and implementation mechanisms of the Strategy.
(A) Proposed amendment to the Strategy: Section 3.3.1 – Governance Structure should include explicit provisions defining the role of the relevant national standardisation entities and mechanisms for integrating European and international standards into the national AI governance and assurance framework.
3. Chips – AI Infrastructure – Quantum Security: The strategic link between Section 3.7.5, “Integration with EuroHPC and the European AI Factory Ecosystem,” and the European semiconductor and chips ecosystem is fundamental (also the Quantum security part). AI capabilities increasingly depend on advanced processors, AI accelerators, heterogeneous computing architectures, chiplets and specialised semiconductor technologies. At the same time, a gap remains between chip-level security engineering and AI infrastructure security. Addressing AI infrastructure security exclusively at the software, platform or application layers would therefore leave an increasingly important part of the AI technology stack insufficiently addressed. Specific provisions should consequently strengthen the integration of chip and chiplet security engineering into national AI activities, including security-by-design, hardware roots of trust, trusted execution, supply-chain assurance, hardware-level resilience, secure lifecycle management and advanced semiconductor security engineering. As AI capabilities and infrastructures continue to expand, the convergence of AI, high-performance computing and trusted semiconductor technologies is becoming strategically important for the security, resilience and technological sovereignty of European and national AI infrastructures. The National AI Strategy should therefore recognise the hardware–software continuum as a fundamental dimension of AI sovereignty, addressing not only algorithms, data, software and computing capacity, but also the trusted semiconductor technologies on which those capabilities ultimately depend.
(a) Proposed amendment to the Strategy:
(A) Section 3.7.5 should include provisions strengthening the connection between AI infrastructure and the chips/chiplet ecosystem supported by tangible implementation actions. These could include, inter alia: (i) strengthening the participation of the Republic of Cyprus and its research and industrial ecosystem in relevant Chips Joint Undertaking (Chips JU) programmes and calls, (ii) supporting national R&D and investment in semiconductor, chiplet, hardware-security and AI-accelerator technologies, (iii) promoting participation in European semiconductor and AI infrastructure value chains, (iv) developing national capabilities in trusted and secure AI hardware, (v) connecting semiconductor research and innovation with EuroHPC, AI Factories and national AI infrastructure initiatives, (vi) supporting the development of a national ecosystem capable of addressing the full AI technology stack, from trusted hardware and computing infrastructure to data, models, applications and services.
(B) AI, Cybersecurity and Quantum Security: Particular consideration should also be given to the convergence of AI, cybersecurity, semiconductor technologies (chip/chiplet) and quantum security. The development of increasingly powerful AI and HPC infrastructures introduces new security dependencies and systemic risks, including those associated with future quantum capabilities and the transition towards post-quantum and quantum-secure technologies. The Strategy should therefore establish a clear connection between the development of national AI capabilities, the chips/chiplet ecosystem, cybersecurity and quantum security, promoting security-by-design across the complete technology stack. This should include consideration of post-quantum cryptography, crypto-agility, trusted hardware, secure key management, hardware-assisted security, quantum-safe migration and, where appropriate, complementary quantum-security technologies. Given the highly cross-cutting nature of these domains, consideration could also be given to the idea of a national capability or coordination function at the intersection of AI, Cybersecurity, Quantum Security and Trusted Semiconductor Technologies. Such a capability could support the national AI ecosystem, monitor technological and security developments, coordinate relevant R&D and innovation activities, strengthen participation in European initiatives, and provide specialised technical expertise to competent national authorities and stakeholders and support the security of Critical Assets of the Republic. The appropriate institutional form i.e Centre of Excellence, specialised competence centre, or another suitable mechanism, should be subject to further analysis, taking into account existing national structures, competencies and European initiatives, with the objective of avoiding duplication while closing identified strategic and technological capability gaps.
HLTF-29. Publish an accessible, version-controlled and authoritative final Strategy
Strategy reference: Whole document; Annexes G–H
Comment type: Transparency / drafting / accessibility
Comment and implementation risk. The 101-page document contains inconsistent body names, undefined frameworks, incomplete citations, drafting errors and a bibliography with no standardisation documents. It is available in English despite being a national public-policy instrument. A strategy that will guide procurement and compliance must have a reliable authoritative version, source hierarchy and amendment history.
Requested amendment. Complete legal and technical editorial review; publish Greek and English versions, accessible formats, source register and change log.
Proposed text for insertion or replacement
Publication, version control and accessibility. Before adoption, the Strategy shall undergo legal, technical, linguistic and accessibility review. The Republic shall publish authoritative Greek and English versions, an accessible HTML version, a concise citizen summary and machine-readable annexes. Each version shall show approval authority, approval date, version number, change history and next review date. Defined terms and institutional names shall be consistent. Citations shall identify complete titles, dates, versions and stable links; primary law and official materials shall take priority over media, vendor and unsourced benchmark claims. Annex H shall include applicable EU and national law, CYS’s legal basis, CEN-CENELEC/ETSI work and relevant ISO/IEC standards. A public correction process shall address errors discovered after adoption.
4. Cross-cutting implementation package
The following package converts the detailed amendments into a practicable delivery sequence. Dates run from final adoption of the Strategy, not from the consultation draft.
Before final adoption
1. Complete legal and technical editorial review; update the AI Act timetable; remove or condition initiatives that lack legal authority.
2. Prepare the concordance with the final national AI implementing law and a definitive governance/RACI schedule.
3. Publish the methodology, comparator selection, evidence register and consultation-response report.
4. Reconcile all KPIs, dates, body names and glossary terms; produce authoritative Greek and English versions.
Within 90 days
1. Publish the Digital Strategy 2020–2025 transition evaluation and current digital/data/cloud/interoperability baseline.
2. Agree cooperation protocols among the Deputy Ministry, competent AI authorities, CYS, the accreditation function, sector regulators and data/cyber authorities.
3. Create the legal-dependency register, public-sector AI inventory and standards roadmap.
4. Issue interim approval gates for legality, FRIA/DPIA, security, procurement, data and architecture.
Within 120–180 days
1. Publish model AI tender and contract schedules, sector implementation dossiers and a national sandbox framework.
2. Cost the delivery portfolio; assign owners; define benefits, stop/scale criteria, independent assurance and evaluation.
3. Launch SME/startup clinics, compute/testing support and standards-participation funding.
4. Complete infrastructure criticality, concentration, energy, water, continuity and exit assessments.
Annually
1. Publish a consolidated report on spending, outcomes, rights impacts, incidents, complaints, standards, market concentration, energy/water and stopped initiatives.
2. Update the law-and-standards register and sector profiles; record every material change to targets, scope or governance.
3. Commission independent evaluation and parliamentary/public scrutiny of high-impact public-sector uses.
4.1 Conditions before the first transformational procurements
Minimum launch gate
No major AI tender should be issued merely to meet the draft eight-month timetable. The minimum package is: named accountable owner; lawful purpose and AI Act classification; current data and system architecture; integrated rights/security assessment; budget and benefits case; standards profile; market and concentration analysis; complete contract schedules; independent assurance route; incident and evidence plan; portability and funded exit; and published decision to proceed.
4.2 Proposed annual assurance statement
The accountable National AI Authority should publish a signed annual statement confirming which commitments were delivered, which were not, material departures from law or standards, unresolved high risks, total expenditure, realised benefits, major incidents and complaints, concentration exposures, and the actions required for the following year. The statement should be subject to independent audit or evaluation appropriate to each claim; it should not be called a conformity certificate unless issued under a defined lawful scheme.
Annex A. Legal and regulatory map
This is a strategy-level map, not an exhaustive statement of applicable law. Each initiative requires a fact-specific legal assessment and review of the current consolidated text of the relevant instrument.
A.1 AI governance. The principal instruments are Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, together with the final Cyprus implementing law. Strategy implementation should address classification, duties by role, authorities, sandboxes, the database, enforcement and timing.
A.2 Data and privacy. The relevant framework includes the GDPR, Data Governance Act, Data Act, Open Data Directive, EHDS and ePrivacy rules. Strategy implementation should address lawful access, roles, purpose, data rights, data spaces and health data.
A.3 Cyber and resilience. The principal instruments are NIS2, the CER Directive, the EU Cybersecurity Act, the Cyber Resilience Act and DORA. Strategy implementation should address criticality, incident response, supply-chain requirements and operational resilience.
A.4 Identity and evidence. The relevant framework includes eIDAS, as amended by Regulation (EU) 2024/1183, together with national evidence and procedural law. Strategy implementation should address identity, signatures, time stamps, ledgers, archiving and admissibility.
A.5 Intellectual property and confidentiality. The relevant instruments include the DSM Copyright Directive, Database Directive, Trade Secrets Directive and the AI Act GPAI duties. Strategy implementation should address training data, text-and-data-mining reservations, provenance, licences and confidential inputs.
A.6 Liability and consumers. The relevant framework includes Directive (EU) 2024/2853, the GPSR, the consumer acquis and national contract and tort law. Strategy implementation should address software and AI product liability, disclosure, remedies and allocation of contractual responsibility.
A.7 Markets and procurement. The relevant framework includes the 2014 procurement directives, State-aid law, the DMA and sector-specific competition law. Strategy implementation should address neutral specifications, proportionality, contestability, subsidies and the avoidance of lock-in.
A.8 Sector overlays. Sector-specific requirements may arise under the MDR/IVDR, MiCA, the DLT Pilot Regime, the AML package, machinery legislation and other applicable sectoral law. Strategy implementation should address product, financial, professional and safety authorisations.
A.9 Fundamental rights. The relevant framework includes the Cyprus Constitution, the EU Charter, the ECHR, and applicable equality, accessibility and child-rights law. Strategy implementation should address necessity, proportionality, fair process, reasons, human review and effective remedy.
Annex B. Standards architecture
Standards should be selected by legal role, intended use, system risk and sector. The references below are illustrative anchors for the national roadmap. Edition status, adoption as a European or Cyprus standard, and any OJEU citation must be checked at the time of use.
B.1 Management and governance. Illustrative standards routes include ISO/IEC 42001:2023 and ISO/IEC 38507:2022. These should be used for organisational systems and governing-body guidance and should not be treated as automatically establishing conformity with the AI Act.
B.2 Risk and impact. Illustrative standards routes include ISO/IEC 23894:2023 and ISO/IEC 42005:2025. These should be used for risk-management and impact-assessment guidance.
B.3 Lifecycle and data. Illustrative standards routes include ISO/IEC 5338:2023 and the ISO/IEC 5259 series. These should be used for lifecycle processes and data-quality governance and processes.
B.4 Security. ISO/IEC 27001:2022 and relevant controls from the ISO/IEC 27000 series provide illustrative standards routes for information-security management and selected cloud and privacy controls.
B.5 AI Act harmonisation. CEN-CENELEC JTC 21 deliverables should be monitored for adoption and OJEU citation. A presumption of conformity should be attributed only within the scope that is actually cited.
B.6 Distributed systems. Relevant work from ISO/TC 307, CEN/CLC JTC 19 and ETSI should be considered for DLT terminology, architecture, governance, interoperability and sector application.
B.7 Forensic readiness. Relevant ISO/IEC digital-evidence standards and emerging AI/DLT work should be considered for evidence identification, preservation, analysis, auditability and incident reconstruction.
B.8 Proposed national standards mechanism
CYS should convene a funded National AI Standards Roadmap with public authorities, industry, startups, academia, professions, workers, consumers and civil society. It should maintain a standards inventory, gap analysis, national positions, delegation support, training plan, procurement profiles and annual adoption report. Cyprus should contribute early to European and international work – including AI/DLT convergence and forensic evidence – while avoiding claims that work in development already constitutes a published or harmonised standard.
Annex C. Authoritative sources
Principal sources reviewed or relied upon. Online sources were checked on 30 August 2026. The final Strategy should cite the current consolidated legal text and current edition/status of standards at implementation.
1. Cyprus National AI Strategy 2032 – consultation text (101 pages)
2. Draft Cyprus law implementing Regulation (EU) 2024/1689 – consultation opened 16 August 2026
3. CYS – official role as Cyprus’s National Standardisation Body
4. Law 156(I)/2002 on standardisation, accreditation and technical information (copy reviewed)
5. Cyprus National Digital Strategy 2020–2025
6. Cyprus National Digital Decade Strategic Roadmap – 2024 revision
7. European Commission – Cyprus 2026 Digital Decade Country Report
8. Regulation (EU) 2024/1689 (Artificial Intelligence Act)
9. Regulation (EU) 2026/1744 (Digital Omnibus on AI)
10. European Commission – current AI Act framework and application timeline
11. European Commission – standardisation under the AI Act
12. CEN-CENELEC – JTC 21 Artificial Intelligence
13. ISO/IEC 42001:2023 – AI management systems
14. ISO/IEC 23894:2023 – AI risk management
15. ISO/IEC 42005:2025 – AI system impact assessment
16. ISO/IEC 5338:2023 – AI system lifecycle processes
17. ISO/IEC 38507:2022 – governance implications of AI
18. ISO/IEC 5259-5:2025 – data quality governance for analytics and ML
19. Regulation (EU) 2016/679 (GDPR)
20. Regulation (EU) 2022/868 (Data Governance Act)
21. Regulation (EU) 2023/2854 (Data Act)
22. Regulation (EU) 2025/327 (European Health Data Space)
23. Directive (EU) 2022/2555 (NIS2)
24. Directive (EU) 2022/2557 (critical entities resilience)
25. Regulation (EU) 2024/2847 (Cyber Resilience Act)
26. Regulation (EU) 2024/1183 (European Digital Identity Framework / eIDAS amendment)
27. Directive (EU) 2019/790 (copyright in the Digital Single Market)
28. Directive (EU) 2024/2853 (liability for defective products)
29. EU Charter of Fundamental Rights, Article 47
30. European Commission – Better Regulation
Document basis and limitations
This submission is a public-policy contribution based on the consultation materials supplied and sources available at the review cut-off. It does not constitute client-specific legal advice, a conformity assessment or a certification. References to proposed Cyprus legislation are to consultation drafts and must be updated against the enacted text. References to standards do not reproduce their copyrighted content and do not imply that every listed standard is applicable to every AI system.
THE HYBRID LAWTECH FIRM
empowered by Christiana Aristidou LLC
Submission focus: Law, regulation, standards, emerging technologies, startups and responsible innovation
Prepared for the public consultation on the Cyprus National AI Strategy 2032. Submission date: 30 August 2026. Consultation deadline: 31 August 2026.
PUBLIC CONSULTATION
SUBMISSION
Cyprus National AI Strategy 2032
Legal, regulatory, policy and implementation amendments
Submitted by: THE HYBRID LAWTECH FIRM, empowered by Christiana Aristidou LLC
Consultation: National AI Strategy of the Republic of Cyprus to 2032
Consultation deadline: 31 August 2026
Submission date: 30 August 2026
Review cut-off: Law, policy, standards and published consultation material available by 30 August 2026
Scope: Legal architecture, regulatory coherence, standardisation, public policy, emerging-technology convergence, compliance, procurement, startups and delivery
Recognition of the Strategy’s strengths
THE HYBRID LAWTECH FIRM recognises the substantial work undertaken to develop a comprehensive national vision to 2032. The Strategy contains many very positive and forward-looking elements, particularly its commitments to trustworthy and human-centred AI, productivity, skills, research, public-service transformation, secure infrastructure, responsible governance and international cooperation. It gives Cyprus an important platform from which to build. This submission seeks to preserve those strengths and provide the legal, regulatory, standards and delivery architecture needed to make them implementable and internationally credible.
Bottom line
The Strategy’s ambition and strong elements should be retained. Before final adoption, however, it needs targeted but material refinement: a current policy baseline; concordance with the draft 2026 national AI implementing law and the enacted framework; clear institutional mandates; accurate treatment of law, standards and assurance; integrated rights, data, cybersecurity, procurement, liability and evidence controls; explicit treatment of technology convergence; and a costed, sequenced delivery plan. Flagship proposals must be reframed wherever a strategy cannot itself create regulatory approvals, EU-wide legal presumptions, judicial powers, certification status, legal equivalence or safe harbours. With these amendments, the Strategy can become a strong, executable foundation for trusted AI in Cyprus.
Contents
1. Executive position
2. Assessment framework
3. Detailed consultation comments
4. Cross-cutting implementation package
Annex A. Legal and regulatory map
Annex B. Standards architecture
Annex C. Authoritative sources
How to use this document
Section 1 may be pasted into the platform’s general-comment field. Each HLTF entry in Section 3 is self-contained and can be submitted against the identified Strategy section. Proposed wording is drafted for direct insertion or adaptation by the drafting authority.
1. Executive position
THE HYBRID LAWTECH FIRM welcomes the substantial work undertaken to develop the Strategy and supports its objective of positioning Cyprus as a trustworthy, innovative and internationally connected jurisdiction for artificial intelligence. The draft contains many valuable and forward-looking elements. It does not yet, however, provide a sufficiently coherent legal and delivery architecture for a national strategy extending to 2032. Its principal weakness is not a lack of ideas or ambition; it is the absence of sufficiently disciplined boundaries between law, policy, standards, certification, institutional power, evidence and implementation.
The final Strategy should be amended before adoption. In particular, it should no longer state without qualification that it builds on the National Digital Strategy 2020–2025. That strategy had expired before this consultation. The legally and strategically sound response is not to declare the AI Strategy automatically invalid, but to require a published transition evaluation and a live baseline connected to the National Digital Decade Strategic Roadmap and any formally adopted successor instruments.
The sequencing of national measures also matters. A draft law implementing Regulation (EU) 2024/1689 was placed in public consultation on 16 August 2026 while the Strategy consultation remained open. That Bill identifies competent, notifying, market-surveillance, accreditation and sandbox functions. The final Strategy must therefore be conformed to the enacted national framework. A policy document should not anticipate, duplicate or contradict statutory mandates.
The Strategy should also treat standardisation as implementation infrastructure, expressly recognise CYS and the national delegation/mirror-committee mechanism, and distinguish voluntary international standards from European harmonised standards cited in the Official Journal. This is essential to make governance, procurement, testing, evidence, interoperability, training and market access operational – not merely aspirational.
1.1 Text for the general-comment field
THE HYBRID LAWTECH FIRM, empowered by Christiana Aristidou LLC, recognises the substantial work undertaken to prepare the Cyprus National AI Strategy 2032, welcomes its many positive and forward-looking elements, and supports its ambition. This submission seeks to preserve those strengths while recommending the material amendments needed before final adoption. The Strategy should be converted from a broad catalogue of aspirations into a legally coherent, costed and accountable delivery framework. First, it should replace unqualified reliance on the expired National Digital Strategy 2020–2025 with a published transition evaluation and a current baseline linked to Cyprus’s National Digital Decade Strategic Roadmap and any formally adopted successor policies. Secondly, following publication of the draft national law implementing Regulation (EU) 2024/1689 during this consultation, the final Strategy should include a formal concordance with the enacted law and should distinguish policy coordination from statutory regulation, market surveillance, accreditation, certification, enforcement and regulatory-sandbox functions. Thirdly, it should accurately distinguish binding law, European harmonised standards, other European and international standards, professional credentials and government guidance; recognise CYS and Cyprus’s national delegates; correct the treatment of ISO/IEC 42001; and establish a standards roadmap covering CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42, ETSI and relevant DLT, cybersecurity and sector committees. Fourthly, major initiatives should pass integrated legality, fundamental-rights, data-protection, equality, accessibility, security, procurement, competition, liability, evidence and sustainability gates. Claims concerning an ‘AI judge’, EU-wide ownership presumptions through AIREG, AML certificates that enable reliance, pre-certification and international equivalence should be deleted or reframed within applicable law. Finally, the Strategy should address the convergence of AI with blockchain/DLT, smart contracts, digital identity and trust services, IoT, digital twins, cloud-edge/HPC, robotics and cybersecurity through technology-neutral architectures and use-case tests. Delivery should be supported by named owners, budgets, baselines, model procurement clauses, SME pathways, public registers, independent evaluation and an annual legal/standards update. These changes would preserve ambition while materially increasing lawfulness, implementability, investor confidence, public trust and international interoperability.
1.2 Priority amendments
1. Legal concordance: Conform governance, powers, sandboxes and enforcement to the final 2026 implementing law.
2. Current policy baseline: Replace unqualified reliance on the expired 2020–2025 Digital Strategy with an evaluated transition and current roadmap.
3. Clear legal hierarchy: Separate binding law, harmonised standards, voluntary standards, guidance and aspirational programmes.
4. Institutional integrity: Publish a RACI and separate sponsor, operator, assurance, accreditation, certification and enforcement functions.
5. Rights-by-design: Apply integrated legality, FRIA/DPIA, equality, accessibility and remedy gates before public-sector use.
6. Procurement controls: Adopt mandatory AI tender and contract clauses before launching transformational procurements.
7. Data governance: Create lawful, federated and documented access rules rather than relying on the metaphor of State ownership.
8. Critical infrastructure: Map NIS2/CER/CRA duties, concentration risks, continuity, incident reporting and resource constraints.
9. Convergence: Address AI with DLT, identity, IoT, digital twins, cloud-edge/HPC, robotics, cybersecurity and smart contracts.
10. Correct flagship claims: Recast AI judge, AIREG, AML certificates, pre-certification and equivalence claims within lawful limits.
11. SME scale-up: Provide proportionate clinics, test support, templates, compute and procurement access tied to evidence.
12. Measurable delivery: Cost the portfolio, reconcile KPIs, assign owners and publish independent evaluation and change logs.
1.3 Overall institutional position
1. Regulation creates enforceable duties; standards provide common technical and organisational methods; accreditation attests competence of conformity-assessment bodies; certification evaluates against a defined scheme; policy selects public outcomes. The final Strategy should keep these functions separate and deliberately connected.
2. The Strategy should be technology-neutral but not technology-blind. AI is increasingly embedded in distributed systems. Cyprus can build a defensible niche by combining legal and regulatory capability with active European and international standards participation across AI, DLT and digital evidence.
3. Public trust will depend less on visionary labels than on visible control: lawful authority, transparent procurement, demonstrable evidence, human accountability, complaint routes, secure and portable infrastructure, and the capacity to stop systems that do not deliver safe public value.
2. Assessment framework
This submission reviewed the full Strategy, relevant Cyprus and EU legislation and policy instruments, applicable standardisation materials, the proposed 2026 national AI implementing law, and the public comments available on the consultation platform as at 30 August 2026. Public comments and other consultation materials were used only to identify recurring implementation concerns; the analysis, conclusions and proposed wording are presented independently by THE HYBRID LAWTECH FIRM.
2.1 Five tests applied
1. Legality: Is there an identified competence, legal basis, responsible authority, procedural safeguard and route of review?
2. Regulatory coherence: Does the proposal fit the AI Act as amended, the draft national law, the wider EU digital acquis and sector regulation?
3. Assurance: Can the claimed outcome be evidenced through standards, testing, audit, conformity assessment, records and independent oversight without confusing their legal effects?
4. Deliverability: Are the owner, budget, procurement route, dependencies, skills, infrastructure, contract rights, timeline and stop/scale criteria specified?
5. Future fitness: Does the proposal remain technology-neutral, interoperable, portable, rights-preserving and adaptable to convergence and regulatory change?
2.2 Four-layer drafting rule
The Strategy should apply a four-layer drafting rule that clearly distinguishes law, standards, assurance, and policy and delivery.
Law: EU and Cyprus legislators, together with competent authorities, create duties, powers, procedures, sanctions and legal effects. The Strategy must not imply that a policy statement itself creates a legal power or exemption.
Standards: CEN, CENELEC and ETSI, together with ISO/IEC and the national standards system, provide consensual specifications and, in defined cases, support conformity. The Strategy must not imply that all standards are mandatory or that compliance with a standard automatically confers a presumption of conformity.
Assurance: Accreditation bodies, conformity-assessment bodies, auditors and testing facilities assess competence, evidence or conformity within a defined scope. The Strategy must not imply that participation in a sandbox, laboratory, badge or audit is equivalent to regulatory approval.
Policy and delivery: Government and accountable public bodies set outcomes, fund, procure, coordinate, publish guidance and evaluate. The Strategy must not imply that a proposed programme overrides law, regulators, courts or independent bodies.
2.3 Principal implementability risks
1. Institutional risk: overlapping authority names and functions may produce unlawful delegation, duplicated supervision or conflicted assurance.
2. Reliance risk: users may treat policy labels, registries, credentials or laboratory outputs as legal certification or safe harbour.
3. Procurement risk: ambitious early tenders may entrench proprietary models, weak audit rights and expensive exit before the governance framework exists.
4. Rights risk: high-impact public AI may be piloted without a complete legality, necessity, discrimination, accessibility and remedy analysis.
5. Investment risk: unsupported KPIs and selective international comparisons may weaken credibility with investors, EU institutions and funding evaluators.
6. Infrastructure risk: cloud/model concentration and energy-water constraints may undermine claimed sovereignty and resilience.
7. Evidence risk: insufficient provenance and forensic readiness may make incidents, liability and regulatory investigations difficult to reconstruct.
3. Detailed consultation comments
Each entry below is drafted to stand alone in the public-consultation platform. References are to the numbered sections and descriptive passages of the consultation version of the Strategy. Proposed text may be inserted directly or adapted while preserving the legal distinction and implementation control identified in the comment.
HLTF-01. State the legal status of the Strategy and establish a legal-dependency rule
Strategy reference: Cross-cutting; §§1.1, 2.3.3, 3.3, 3.9.6, 4.3 and Annex A
Comment type: Legal / governance / drafting
Comment and implementation risk. The text alternates between policy language, mandatory language and claims that new authorities, registries, audits, certificates and legal presumptions will exist. A strategy may direct policy and spending, but cannot itself create statutory powers, binding duties, judicial procedures, presumptions of ownership, certification status or regulatory equivalence. Leaving the hierarchy unstated exposes ministries, procurers, businesses and citizens to reliance on propositions that may have no legal basis.
Requested amendment. Insert an interpretation clause that separates law, standards, government policy and proposed initiatives, and make every legally dependent initiative conditional on competence, enactment, funding and impact assessment.
Proposed text for insertion or replacement
Legal status and dependencies. This Strategy is a policy framework. It does not of itself create statutory powers, legal duties, regulatory approvals, evidential presumptions, certification status or rights of reliance. References to ‘shall’ bind public bodies only to the extent authorised by applicable law and a duly approved implementation instrument. Each initiative shall be entered in a public legal-dependency register identifying the legal basis, competent authority, required primary or secondary legislation, applicable EU law, standards profile, budget, accountable owner and commencement condition. No initiative affecting rights, market access, supervision, certification or judicial decision-making shall become operational until those conditions are satisfied.
HLTF-02. Replace the expired digital-strategy foundation with a current, evidenced baseline
Strategy reference: §2.3.2 and footnote 10; §2.2; Annex A
Comment type: Strategic / evidence / drafting
Comment and implementation risk. Section 2.3.2 says the Strategy is aligned with the ‘existing Digital Strategy’, while footnote 10 identifies the National Digital Strategy 2020–2025. That instrument had expired before this 2026–2032 Strategy was consulted. Expiry does not automatically invalidate the AI Strategy, but it makes the asserted foundation incomplete and potentially misleading unless there is an evaluation of delivery, unresolved dependencies and a formal transition to current policy. The document also uses the undefined expression ‘revised Digital Strategy’ elsewhere.
Requested amendment. Delete the unqualified reliance on the expired instrument. Add a transition and baseline annex linked to the National Digital Decade Strategic Roadmap and any successor digital strategy, with version control and an update trigger.
Proposed text for insertion or replacement
Digital-policy baseline. The Strategy takes account of lessons and assets arising from the National Digital Strategy 2020–2025, but does not treat that expired instrument as the current policy foundation. Within 90 days of adoption, the Deputy Ministry shall publish a transition statement that: (a) evaluates the 2020–2025 Strategy against its objectives; (b) identifies completed, continuing, superseded and unimplemented measures; (c) maps dependencies to the current National Digital Decade Strategic Roadmap and any formally adopted successor digital strategy, data strategy, cloud policy and interoperability framework; and (d) reconciles baselines, budgets, owners and dates. References in this Strategy shall identify the title, version, approval date and status of the policy instrument relied upon.
HLTF-03. Make the methodology, country benchmarking and evidence base reproducible
Strategy reference: §§1.6–1.7; sector ‘International alignment’ passages; Annex H
Comment type: Policy / evidence / international relations
Comment and implementation risk. The Strategy names a small set of countries as ‘pioneers’ and states that selected national strategies informed the work, but gives no selection criteria, comparator groups, variables, time periods, performance evidence or transferability test. Comparative learning is valuable; selective endorsement without a method may imply an official ranking, overlook relevant Member States and create unnecessary reputational or competitive signalling. The listed meetings likewise do not amount to a published stakeholder map, evidence register or impact assessment.
Requested amendment. Replace country praise with a neutral benchmarking method and publish the evidence, assumptions, limitations and consultation-response report.
Proposed text for insertion or replacement
Comparative and consultation methodology. International examples shall be used as evidence sources, not as country rankings or general endorsements. A benchmarking annex shall identify the policy question, transparent selection criteria, peer group, indicators, data year, source quality, implementation outcomes, Cyprus transferability constraints and limitations for each comparator. The final Strategy shall include an evidence register, stakeholder-category map, summary of options considered, principal assumptions, distributional and fundamental-rights impacts, and a reasoned consultation report explaining which material comments were accepted, partly accepted or rejected. Country references unsupported by that method shall be removed or expressed neutrally.
HLTF-04. Conform the Strategy to the 2026 draft AI implementing law and the final enacted framework
Strategy reference: §3.3.1; §3.9.6; §§3.13–4.3; Annexes A–C
Comment type: Legal / institutional sequencing
Comment and implementation risk. The proposed national law for implementing Regulation (EU) 2024/1689 was published for consultation on 16 August 2026, during the Strategy consultation. It allocates functions to the Commissioner of Electronic Communications, the Commissioner for Personal Data Protection, the Central Bank and any further designated authority; identifies the national accreditation function; and provides a national regulatory-sandbox mechanism. The Strategy instead creates or names bodies with overlapping regulatory, audit, registry, certification and sandbox functions. The two instruments cannot safely proceed on parallel, inconsistent institutional assumptions.
Requested amendment. Require a formal concordance after the Bill is finalised, preserve the authority of the legislature and regulators, and distinguish policy coordination from statutory supervision.
Proposed text for insertion or replacement
Institutional concordance. Before the Strategy is submitted for final approval, and again following enactment of the national law implementing Regulation (EU) 2024/1689, the Attorney-General’s Office and the responsible Deputy Ministry shall complete and publish an article-by-article concordance table. It shall map every Strategy body and function to the competent authority, legal basis, accountability route, appeal or complaint mechanism, information-sharing power and funding source. Strategy bodies may coordinate policy and delivery but shall not exercise market-surveillance, notifying-authority, accreditation, certification, enforcement, complaints, sanctioning or regulatory-sandbox powers unless those powers are expressly conferred by applicable law. Any inconsistent Strategy wording shall be amended automatically through a published conformance update.
HLTF-05. Clarify governance, names, accountability and separation of functions
Strategy reference: §§3.3.1–3.3.2; glossary; Annex B
Comment type: Governance / administrative law
Comment and implementation risk. The governance architecture uses inconsistent names and roles, including ‘Council’ and ‘Committee’, and describes the Taskforce both as independent advisory body and central coordinating body. The National AI Authority is simultaneously presented as policy coordinator, executor and control gatekeeper. Other entities prototype, validate, procure, approve, monitor or certify. Without a single responsibility matrix, the same institution may sponsor a system and assure it, weakening independence and creating conflicts.
Requested amendment. Publish a definitive governance schedule and apply separation of policy, delivery, assurance and enforcement.
Proposed text for insertion or replacement
Governance and separation of functions. Annex A shall contain the definitive name, legal form, mandate, membership, appointment process, term, conflicts policy, decision rights, reporting line, budget and review date for every Strategy body. A RACI matrix shall cover policy, funding, procurement, data access, development, deployment approval, conformity assessment, audit, incident response, market surveillance and redress. No body that develops, funds, procures or operates an AI system shall provide the final independent assurance or statutory enforcement decision for that same system. Duplicate names and inconsistent glossary definitions shall be corrected. Existing constitutional, ministerial, regulatory, judicial and independent-authority competences remain unaffected.
HLTF-06. Recognise CYS and preserve the national quality-infrastructure boundaries
Strategy reference: §§1.4.3–1.4.10, 2.5.1, 3.3.1, 3.12; §4.3; Annexes A, C and H
Comment type: Legal / standards / institutional
Comment and implementation risk. Formal standardisation is treated intermittently, CYS is not assigned a role, and ‘standards’ are sometimes described as outputs of the proposed National AI Authority. CYS is Cyprus’s official National Standardisation Body and exercises the national standardisation activity pursuant to Law 156(I)/2002, including national coordination and representation in CEN, CENELEC, ISO and IEC. Standardisation, accreditation, conformity assessment/certification, regulation and policy guidance are related but legally distinct functions.
Requested amendment. Insert CYS into the governance and implementation architecture as standards coordinator, while expressly preserving the roles of regulators, the national accreditation body and conformity-assessment bodies.
Proposed text for insertion or replacement
National standardisation and quality infrastructure. CYS, as Cyprus’s official National Standardisation Body exercising the national standardisation activity pursuant to Law 156(I)/2002, shall coordinate national standards intelligence, national mirror-committee participation, adoption of European standards and access to international standards work relevant to this Strategy. The National AI Authority may issue policy frameworks, implementation guidance and common administrative controls, but shall not present those instruments as national, European, harmonised or international standards. Accreditation shall remain with the legally designated national accreditation body; certification and conformity assessment shall be performed only by competent bodies under applicable schemes; and statutory supervision shall remain with the competent authorities. A written cooperation protocol shall prevent overlap.
HLTF-07. Correct the legal effect and technical description of standards
Strategy reference: §§2.3.4, 3.11.2, 3.12.4, 3.13.1–3.13.3; Annex A; Annex H
Comment type: Technical / legal accuracy
Comment and implementation risk. The Strategy recommends ‘ISO 42001 as a standard for risk management’, treats ISO/IEC 27001 as if it were sufficient for AI security, and places the AIGP professional credential alongside standards. ISO/IEC 42001 is an AI management-system standard; ISO/IEC 23894 is dedicated AI risk-management guidance. A voluntary standard does not itself prove compliance with the AI Act. Under Article 40 of the AI Act, only an applicable harmonised standard or part cited in the Official Journal may confer the specified presumption of conformity.
Requested amendment. Replace the current wording with a standards taxonomy and risk-based profile; correct Annex H.
Proposed text for insertion or replacement
Use and legal effect of standards. ISO/IEC 42001:2023 may support an organisational AI management system; ISO/IEC 23894:2023 may support AI risk management; ISO/IEC 42005:2025 may support AI system impact assessment; ISO/IEC 5338:2023 may support lifecycle processes; the ISO/IEC 5259 series may support data-quality governance; and ISO/IEC 27001:2022 and related controls may support information security. These references are voluntary unless law or contract makes them applicable. They do not replace legal analysis or automatically demonstrate AI Act conformity. Applicable European harmonised standards developed through CEN-CENELEC JTC 21 shall be monitored and used where appropriate after adoption and, for presumption of conformity, OJEU citation. Professional credentials shall be listed as training credentials, not standards.
HLTF-08. Use the current AI Act and remove blanket registration and obsolete timing claims
Strategy reference: §3.9.6; §§3.11–3.13; Annex A; sector roadmaps
Comment type: EU law / compliance
Comment and implementation risk. The Strategy includes readiness language tied to 2 August 2026, although consultation continues after that date, and says every organisation must register AI systems in the EU database ‘without exception’. Registration under the AI Act is role- and category-specific; it is not a universal registry duty. The legal timetable was also amended by Regulation (EU) 2026/1744, which entered into force on 27 July 2026. Static or inaccurate dates will make a 2032 strategy obsolete immediately.
Requested amendment. Replace blanket claims with a maintained obligations register based on the AI Act as amended.
Proposed text for insertion or replacement
AI Act implementation register. All references to Regulation (EU) 2024/1689 shall mean that Regulation as amended, including Regulation (EU) 2026/1744, and any applicable delegated or implementing acts. The National AI Authority shall maintain, with the competent authorities, a dated public implementation register identifying obligations by role, system category and commencement date. Registration in the EU database or any national register shall be required only where applicable law requires it. The national implementation plan shall distinguish prohibited practices, transparency obligations, general-purpose AI obligations, Annex III high-risk systems, safety components of regulated products, public-authority deployer duties, fundamental-rights authorities and sector-specific law.
HLTF-09. Redesign NAICF, audits and the proposed certification lab around lawful conformity routes
Strategy reference: §3.9.6; Legal Services pillar; §4.3
Comment type: Conformity assessment / legal / market access
Comment and implementation risk. The text proposes annual audits by a ‘Cyprus AI Security & Certification Authority’, a central registry of systems ‘certified under EU rules’, pre-certification of high-risk and ‘foundation’ models, and international equivalence bridges. It does not identify the legal basis, applicable standard, scheme, accreditation, notified-body route, scope of certificate, surveillance, complaints, liability or recognition mechanism. The AI Act uses the term general-purpose AI model and prescribes conformity routes; policy branding cannot create EU recognition or equivalence.
Requested amendment. Convert NAICF into optional readiness support unless and until a lawful scheme is established, and remove ‘pre-certification’, ‘dual recognition’ and blanket annual-audit claims.
Proposed text for insertion or replacement
National AI Compliance Framework. NAICF shall operate as a non-binding readiness, evidence and implementation-support framework unless a specific function is conferred by law. It shall not issue or imply regulatory approval, CE marking, presumption of conformity, notified-body status, accreditation, legal equivalence or safe harbour. Any audit or certification scheme shall identify its owner, normative requirements, competence criteria, accreditation basis, assessment route, scope, validity, surveillance, complaints, impartiality, liability and relationship to Articles 40–49 of the AI Act. The proposed laboratory may provide testing, evaluation and sandbox support; the terms ‘pre-certification’, ‘certified under EU rules’, ‘dual recognition’ and ‘foundation model’ shall be replaced by legally accurate descriptions.
HLTF-10. Create an integrated fundamental-rights and public-law assurance gate
Strategy reference: §§1.4.8, 2.5.5, 3.3.2, 3.9, 3.13; Annex B
Comment type: Fundamental rights / administrative law
Comment and implementation risk. The Strategy refers generally to ethics, fairness and mandatory legal assessments for high-impact systems but does not specify decision criteria, responsible officials, publication rules or interaction with the AI Act fundamental-rights impact assessment, GDPR data-protection impact assessment, equality, accessibility, children’s rights and administrative-law duties. ‘Ethics’ cannot replace legality, and a checklist cannot legitimise a use that lacks statutory competence or necessity.
Requested amendment. Add one integrated, risk-based assessment and approval gate before procurement and deployment of high-impact public-sector AI.
Proposed text for insertion or replacement
Integrated rights and legality assessment. Before procurement, pilot or deployment of high-impact public-sector AI, the accountable public body shall document: legal competence and purpose; necessity and proportionality; AI Act classification and any required fundamental-rights impact assessment; GDPR lawful basis, Article 22 analysis and any required DPIA; equality and non-discrimination; accessibility; child and vulnerable-person safeguards; human decision authority; notice, reasons, review, complaint and remedy; security; evidential integrity; and less intrusive alternatives. The assessment shall be reviewed by the competent legal, data-protection, security and domain functions. A non-confidential summary and decision shall be published, subject only to lawful restrictions. Ethics review supplements and does not replace legal compliance.
HLTF-11. Establish a lawful public-sector AI register, notice, human review and redress
Strategy reference: §§3.3.2, 3.4, 3.9.6; Annexes B–C
Comment type: Transparency / public law / rights
Comment and implementation risk. The proposed ‘AI Registry’ is framed as cataloguing all market solutions, but no purpose, legal basis, scope, confidentiality rule or relationship with EU registration is defined. Citizens need transparency about State use, while businesses require protection of trade secrets and security information. Article 86 of the AI Act provides a limited right to explanation in specified circumstances; it should not be expanded or reduced by imprecise strategy language.
Requested amendment. Create a public-sector register first, avoid duplicate filings, and define individual safeguards in legally accurate terms.
Proposed text for insertion or replacement
Public-sector AI transparency and redress. Cyprus shall maintain a public register of AI systems used by public bodies, linked where practicable to required EU registrations and avoiding duplicate filings. Each entry shall identify the accountable body, purpose, provider and material subcontractors, legal basis, AI Act classification, affected groups, data categories, human-oversight model, impact-assessment status, performance indicators, material incidents, procurement reference and complaint channel. Security-sensitive and protected commercial information may be withheld only on a documented legal basis. Affected persons shall receive meaningful notice and access to human review, reasons or explanation, complaint and judicial or administrative remedy to the extent provided by applicable law, without limiting stronger rights under other law. Non-digital service channels shall remain available for essential services.
HLTF-12. Recast data as a governed resource rather than an unqualified national asset
Strategy reference: §3.2; §3.7; sector data proposals; Annex A
Comment type: Data law / governance / interoperability
Comment and implementation risk. Calling data a ‘strategic national asset’ may be a useful policy metaphor but does not determine ownership, lawful access or reuse. The proposed lake, warehouse and hub model lacks a legal classification of personal, non-personal, confidential, open, sectoral and protected data; a controller/processor map; purpose and access rules; retention; provenance; data-quality metrics; rights management; and a decision between centralised and federated architecture.
Requested amendment. Insert a national AI data-governance framework aligned with the GDPR and the EU data acquis, and require data-product documentation.
Proposed text for insertion or replacement
Data governance for AI. Data shall be treated as a governed public-interest resource where law permits, not as property of the State by default. Before access or reuse, each dataset shall have a named steward; legal and rights classification; controller/processor or other role allocation; purpose and lawful basis; provenance; quality and representativeness measures; access conditions; licensing and intellectual-property status; retention and deletion rule; security classification; data-subject or third-party rights process; and audit record. Architecture shall favour federated access, minimisation and purpose limitation where centralisation is unnecessary. The framework shall align, as applicable, with the GDPR, Data Governance Act, Data Act, Open Data Directive, EHDS, trade-secret and copyright law, sector confidentiality and the European Interoperability Framework, supported by the ISO/IEC 5259 series and relevant European standards.
HLTF-13. Make public procurement the principal implementation control
Strategy reference: §§3.3.2, 3.4.1, 4.1; first six transformational procurements; Annex B
Comment type: Public procurement / contracts / implementation
Comment and implementation risk. The Strategy proposes six transformational procurements within eight months and an ‘AI-first’ procurement direction, but does not supply minimum readiness gates or contract terms. Buying quickly before requirements, data rights, interfaces, evidence and exit are defined can lock the State into providers and shift compliance risk to taxpayers. ‘AI-first’ may also bias problem definition toward technology instead of public value and proportionality.
Requested amendment. Replace ‘AI-first’ with problem-led, outcome-based and rights-preserving procurement, and publish mandatory clauses before major tenders.
Proposed text for insertion or replacement
AI procurement standard. Public bodies shall procure AI only where a documented problem, lawful purpose and proportionate business case show that AI is suitable compared with non-AI alternatives. Before tender, the body shall complete classification, data-readiness, rights, security, accessibility, competition and exit assessments. Mandatory contract schedules shall address: provider/deployer roles; model and material-subcontractor transparency; data, input and output rights; training and improvement use; logging and evidence retention; performance and bias testing; human oversight; cybersecurity; incident and regulator cooperation; material model-change control; audit access; service levels; intellectual property; confidentiality; product and professional liability; insurance; portability, open formats, interfaces and exit assistance; deletion/return of data; sustainability metrics; and termination. No transformational procurement shall launch until these templates and an independent assurance route are approved.
HLTF-14. Unify regulatory sandboxes, testbeds and innovation facilities
Strategy reference: §§3.4–3.9; LegalTech and sector sandboxes; §4.3
Comment type: Regulatory governance / innovation
Comment and implementation risk. The Strategy repeatedly proposes sector sandboxes and testing facilities without distinguishing a statutory AI regulatory sandbox from experimentation, testbeds, accelerators, centres of excellence and conformity assessment. The draft implementing Bill assigns the national regulatory sandbox to the identified competent authorities. Multiplying ‘sandboxes’ without a common legal gateway risks regulatory arbitrage, duplicated applications and false impressions of approval.
Requested amendment. Create one national sandbox framework with sector pathways and common entry, exit and publication rules.
Proposed text for insertion or replacement
Sandbox and testing architecture. The national AI regulatory sandbox shall be operated only by the authority or authorities designated by law and in accordance with the AI Act. Sector regulators, the Data Protection Commissioner, CYS, accreditation and conformity-assessment actors, research facilities and domain experts shall participate within their respective competences. Innovation hubs, accelerators and testbeds may provide technical experimentation but shall not imply regulatory approval. A single public framework shall define eligibility, SME and startup support, application criteria, real-world testing conditions, data protection, intellectual property, confidentiality, liability, incident response, standards participation, regulator coordination, duration, exit report, evidential value and the express statement that participation does not remove legal obligations.
HLTF-15. Treat the National AI Infrastructure as a regulated critical dependency
Strategy reference: §§3.7.1–3.7.4 and 3.13.2–3.13.3; Annex A
Comment type: Cybersecurity / resilience / critical infrastructure
Comment and implementation risk. The Strategy describes the National AI Infrastructure as critical national infrastructure but does not map designation, competent authorities or duties under NIS2, the CER Directive, the Cybersecurity Act, the Cyber Resilience Act or sector rules. Generic ‘national cybersecurity frameworks’ are insufficient for shared compute, model access, sensitive data, cross-border cloud, supply-chain threats and systemic concentration.
Requested amendment. Require a criticality and regulatory assessment before architecture or procurement, plus measurable resilience and recovery controls.
Proposed text for insertion or replacement
Critical AI infrastructure assurance. Before design approval, the responsible authority shall determine and publish the legal classification, essential/important-entity status, critical-entity dependencies and competent supervisory arrangements for each infrastructure component under NIS2, the CER Directive, applicable Cyprus law, the EU Cybersecurity Act, the Cyber Resilience Act and sector regimes. Architecture and procurement shall include zero-trust access, tenant isolation, secure development, model and data supply-chain controls, vulnerability handling, cryptographic agility, adversarial testing, logging, forensic readiness, continuity, geographic and provider concentration limits, tested recovery objectives, portability and exit, incident-reporting interfaces and independent security evaluation. ENISA guidance and applicable standards shall be tracked in a maintained control profile.
HLTF-16. Define digital sovereignty through measurable control, competition and exit
Strategy reference: §3.7.3; public-sector platforms; Annex C
Comment type: Competition / cloud / strategic autonomy
Comment and implementation risk. ‘Digital sovereignty’ is defined at a high level and then associated with specific infrastructure choices. Sovereignty is not achieved merely through local hosting, ownership or a favoured hardware architecture. A system may be physically local yet operationally dependent on a foreign hyperscaler, proprietary model, unavailable weights, non-portable data or a single integrator. Conversely, carefully governed European or cross-border services may increase resilience.
Requested amendment. Adopt outcome-based sovereignty criteria and technology-neutral procurement.
Proposed text for insertion or replacement
Digital sovereignty and contestability. Sovereignty shall be measured by lawful control over data and keys; ability to audit and govern models; continuity under supplier failure or geopolitical disruption; portability of data, prompts, logs, configurations and workloads; open and documented interfaces; substitutability of critical components; availability of skills and maintenance; compliance with EU law; and tested exit within defined time and cost. Procurement shall be technology-neutral and shall not prescribe a processor, model or distributed architecture without a published proportionality, security, competition and lifecycle-cost assessment. Multi-cloud or sovereign-cloud claims shall be evidenced, and material provider/model concentration shall be reported annually.
HLTF-17. Add a technology-convergence and distributed-systems strategy
Strategy reference: §§1.3–1.4, 2.3.4, 3.7, 3.12; sector roadmaps
Comment type: Emerging technology / standards / strategic
Comment and implementation risk. The Strategy largely treats AI as a standalone technology even though implementation will depend on cloud-edge/HPC, IoT, robotics, digital twins, digital identity and trust services, cybersecurity, smart contracts, tokenisation and blockchain/DLT. The absence is especially striking where the text already proposes a blockchain registry. Convergence affects architecture, evidence, security, liability, interoperability and skills; it should not be addressed through isolated use cases.
Requested amendment. Insert a horizontal, technology-neutral convergence section with a use-case test and coordinated standards participation.
Proposed text for insertion or replacement
Converging technology systems. Cyprus shall govern AI as part of distributed socio-technical systems that may combine cloud and edge computing, high-performance computing, IoT, digital twins, robotics and autonomous systems, digital identity and trust services, cybersecurity, smart contracts, tokenisation and blockchain/DLT. Each proposed combination shall pass a documented use-case test covering necessity, comparative architecture, legal roles, data flows, security, interoperability, environmental cost, governance, evidence and exit. DLT shall be used only where distributed control, tamper-evidence or shared state provides demonstrable value over a conventional database. CYS shall coordinate relevant participation across ISO/IEC JTC 1/SC 42, ISO/TC 307, CEN-CENELEC JTC 21, CEN/CLC JTC 19, ETSI and sector committees so that common system descriptions and interfaces can be developed without displacing committee competence.
HLTF-18. Correct AIREG: DLT records can support evidence, not manufacture ownership
Strategy reference: Legal Services pillar, pp. 74–76; AIREG
Comment type: Intellectual property / evidence / DLT
Comment and implementation risk. AIREG is said to provide ‘immutable certification’ and a strong presumption of ownership across the EU. A ledger entry can help prove that a particular hash or assertion existed at a time and has not been altered. It does not establish authorship, originality, title, lawful training, absence of infringement or the truth of the recorded claim, and a Cyprus strategy cannot create an EU-wide ownership presumption. Immutability also conflicts with rectification, revocation, key compromise and data-protection requirements if designed poorly.
Requested amendment. Recast AIREG as a feasibility study for a rights-evidence and provenance service aligned with eIDAS and IP law.
Proposed text for insertion or replacement
AI provenance and rights-evidence feasibility study. The proposed AIREG shall not be described as certifying ownership or creating a legal presumption across the Union. A feasibility study shall compare conventional and DLT architectures and assess legal basis, governance, evidential effect, identity assurance, time-stamping, qualified electronic ledgers and archiving under eIDAS as amended, WIPO and EU intellectual-property rules, GDPR, trade secrets, cybersecurity, interoperability, correction and revocation, key loss, dispute resolution, liability and long-term preservation. Any pilot may record signed claims, hashes, provenance events and licences, but shall state that technical integrity does not prove the truth, lawfulness, authorship or ownership of the underlying asset. Legal effect shall arise only from applicable law and admissible evidence.
HLTF-19. Remove the ‘AI Judge’ commitment pending constitutional and justice-system reform
Strategy reference: Legal Services pillar, pp. 74–76; Annex C
Comment type: Constitutional / judicial / fundamental rights
Comment and implementation risk. The proposal for an ‘AI judge’ in low-value, factually uncontested cases is not a mere digital-service project. It concerns the exercise of judicial power, independence and impartiality, Article 30 of the Constitution, Article 47 of the EU Charter, Article 6 ECHR, procedural law, open justice, evidence, reasons, appeal and equality of arms. Monetary value and absence of a factual dispute do not remove questions of law or vulnerability. AI used to prepare judicial decisions is also a high-risk category under the AI Act.
Requested amendment. Delete the commitment to an AI judge. Permit carefully governed administrative and judicial support only, unless future primary law and constitutional analysis authorise more.
Proposed text for insertion or replacement
Justice-sector AI. The term and proposal ‘AI Judge Capability’ shall be deleted. AI may be evaluated for transcription, translation, scheduling, search, document triage, legal research and non-binding decision support, subject to judicial governance, procurement, security, evidence, data protection, professional secrecy, accessibility and fundamental-rights safeguards. A natural judge or legally authorised decision-maker shall retain responsibility for the decision, factual and legal assessment, reasons and remedy. Any future proposal for automated adjudication shall require a separate public justice strategy, constitutional and human-rights opinion, primary legal basis, judicial and Bar consultation, equality and accessibility assessment, pilot evaluation, public transparency and an effective right to human determination and appeal.
HLTF-20. Govern court transcription and a Cyprus case-law model as justice infrastructure
Strategy reference: Legal Services pillar, pp. 74–76
Comment type: Justice / data / evidence / procurement
Comment and implementation risk. AI transcription and a case-law language model can improve access, but the current text does not address authoritative records, correction, speaker identification, protected hearings, anonymisation, hallucinations, source citation, copyright/database rights, judicial independence, professional secrecy or whether citizens may rely on outputs. A model trained on incomplete or non-authoritative judgments may entrench error.
Requested amendment. Add a justice-data governance and staged evaluation programme; never label model output as authoritative legal advice or an official judgment.
Proposed text for insertion or replacement
Court records and case-law AI. The Supreme Court and competent justice authorities shall own governance of any transcription or case-law AI service. A pilot shall define the authoritative record, human verification, correction procedure, source provenance, citation to the controlling judgment, coverage limitations, protected-hearing controls, anonymisation, retention, access tiers, cybersecurity, professional secrecy, copyright and database rights, model evaluation and incident response. Public outputs shall disclose that they are generated or assisted by AI and are not the authoritative judgment or legal advice. No system shall train on confidential material or use court data for provider model improvement without express legal and contractual authority. Independent accuracy, language and equality testing shall precede scale-up.
HLTF-21. Limit the Digital AML Certification Scheme to interoperable evidence exchange
Strategy reference: Legal Services pillar, pp. 74–76; Financial Services pillar
Comment type: AML / financial regulation / liability
Comment and implementation risk. The proposed certificate would ‘enable reliance’ by obliged entities and authorities. Under EU and national AML rules, reliance, outsourcing and information exchange do not automatically transfer each obliged entity’s responsibility for customer due diligence, risk assessment, monitoring, sanctions controls and suspicious-activity reporting. A certificate may become stale, be wrong, reveal sensitive data or create systemic reliance on one provider.
Requested amendment. Reframe the initiative as a regulated, revocable and purpose-limited evidence exchange; do not promise discharge from AML duties.
Proposed text for insertion or replacement
Digital AML evidence exchange. Any Digital AML Certification Scheme shall be developed with the competent AML supervisors, Data Protection Commissioner and obliged-sector representatives, and aligned with the applicable EU AML package, GDPR, eIDAS, DORA and sector secrecy. It may support interoperable, verifiable and time-bounded exchange of specified due-diligence evidence, but shall not state or imply that an obliged entity is discharged from its own legal duties. The scheme shall define issuer competence, assurance level, data minimisation, consent or other legal basis, permitted reliance, freshness, revocation, sanctions and PEP updates, correction, audit, liability allocation, regulator access, cross-border transfer, cyber incident handling and alternatives for persons unable to use the service.
HLTF-22. Add a complete intellectual-property, trade-secret and AI value-chain framework
Strategy reference: §§3.2, 3.5, 3.11; Legal Services pillar; Annex A
Comment type: IP / commercial law / GPAI
Comment and implementation risk. The Strategy proposes clarifying protection for ‘computer-generated works’ but does not address the full value chain: training-data acquisition and text-and-data-mining reservations; rights in datasets, models, prompts and outputs; open-source licences; employee/contractor ownership; confidential information; model-provider terms; GPAI copyright duties; provenance; infringement allocation and remedies. Creating a bespoke national right without EU-compatibility analysis could fragment the internal market or produce false confidence.
Requested amendment. Replace the narrow promise with an expert review and standard contractual toolkit aligned with EU law.
Proposed text for insertion or replacement
AI intellectual-property and value-chain framework. Cyprus shall undertake an evidence-based review of copyright, database rights, trade secrets, patents, open-source licensing, contractual rights and GPAI obligations across data acquisition, training, fine-tuning, retrieval, deployment and output use. The review shall assess EU competence and harmonisation limits before proposing national legislation. Public procurement and SME support shall include model clauses on authorised data use, text-and-data-mining reservations, provenance, confidential inputs, provider training use, model and output licences, open-source obligations, infringement warranties, notice-and-takedown, indemnities, audit evidence and termination. No registry entry or contractual label shall be presented as creating ownership that applicable law does not recognise.
HLTF-23. Build a proportionate startup and SME compliance-to-scale pathway
Strategy reference: §§2.5.4, 3.5, 4.2–4.3; NAICF Comply and AdoptNAICF
Comment type: Startups / SMEs / investment / State aid
Comment and implementation risk. The Strategy rightly prioritises adoption and funding, but certification-heavy or one-size-fits-all requirements may price startups out before product-market fit. Conversely, grants without legal, procurement and evidence readiness can fund pilots that never scale. National-residency preferences may also conflict with EU procurement, establishment and State-aid rules. Support must follow role, risk and maturity.
Requested amendment. Create staged support from classification to cross-border scale, using lawful access criteria and reusable evidence.
Proposed text for insertion or replacement
Startup and SME implementation pathway. Cyprus shall provide a proportionate, risk-based pathway comprising: free classification and regulatory clinics; AI literacy and standards navigation; model contract and DPIA/FRIA templates; compute and test-data vouchers; access to the statutory sandbox and testing facilities; security and red-team support; procurement-readiness coaching; staged grants tied to evidence and milestones; and support for CE-marking or conformity routes where legally applicable. Requirements shall scale by role, system risk and maturity. Public procurement shall use proportionate turnover, insurance and prior-experience criteria, suitable lotting and transparent challenge-based procedures, without unlawful nationality or residence discrimination. Funding shall address State-aid rules, intellectual property, follow-on finance, commercialisation and measurable additionality.
HLTF-24. Add liability, insurance, incident and forensic-evidence architecture
Strategy reference: §§3.3.2, 3.9, 3.13; Annexes B–C
Comment type: Liability / evidence / enforcement
Comment and implementation risk. The Strategy focuses on controls but not on who bears loss when AI fails. Software and AI are addressed by the revised EU Product Liability Directive, while contract, tort, professional duties, public-law liability and sector rules continue to apply. Dynamic models also require evidence that can reconstruct versions, inputs, outputs, human interventions and post-deployment changes. Ordinary logs may be incomplete or controlled by the supplier.
Requested amendment. Add a liability and evidence workstream before procurement, not after an incident.
Proposed text for insertion or replacement
Liability, insurance and forensic readiness. Every high-impact AI initiative shall maintain a responsibility and liability map covering provider, deployer, importer, distributor, integrator, data supplier, cloud/model provider, professional user and public authority. Procurement shall address the revised Product Liability Directive, applicable contract, tort, professional, public-law and sector liability; evidence disclosure; warranties; indemnities; caps; insurance; limitation periods; and recourse through the supply chain. Systems shall preserve proportionate, secure and admissible evidence of model/version, configuration, data provenance, inputs and outputs, human review, changes, incidents and remediation, with retention and access rules. Cyprus shall support CYS-coordinated participation in relevant AI, DLT and digital-evidence standardisation, including international forensic-evidence work, without predetermining its outcome.
HLTF-25. Make sustainability and island-resource constraints binding investment gates
Strategy reference: §§3.7.1–3.7.4, 3.13; Annexes C and F
Comment type: Sustainability / infrastructure / investment
Comment and implementation risk. Compute ambitions are not tied to an energy, water, land, grid, carbon or hardware-lifecycle baseline. For an island system, data-centre and AI-factory decisions can create material grid and water dependencies, stranded assets and exposure to imported equipment. Generic references to sustainable infrastructure are not enough for investment appraisal.
Requested amendment. Require resource and climate gates for all publicly funded compute and major cloud procurements.
Proposed text for insertion or replacement
Sustainable AI infrastructure. No major public AI compute or data-centre investment shall proceed without a published whole-life assessment of demand, utilisation, alternatives and shared European capacity; grid connection and resilience; energy source and additionality; water availability and WUE; PUE; embodied carbon and equipment lifecycle; heat reuse; land and permitting; supply-chain concentration; climate adaptation; decommissioning; and total public cost. Tenders shall include comparable metrics, metering, reporting, efficiency thresholds and improvement obligations. The National AI Infrastructure Council shall publish annual capacity, utilisation, energy, water, carbon, outage and cost indicators and explain whether local build, federated access or European shared capacity offers the best public value.
HLTF-26. Add labour, professional-responsibility, education and accessibility safeguards
Strategy reference: §§3.4–3.6; Education and Human Capital pillar; Annex C
Comment type: Employment / education / inclusion
Comment and implementation risk. The Strategy promotes augmentation and reskilling but does not provide workforce-impact assessment, worker consultation, protections for algorithmic management, professional accountability, academic integrity or equitable access. AI literacy is a legal obligation in the AI Act but cannot be reduced to tool training. Children, persons with disabilities, non-digital users and workers affected by monitoring or task redesign require specific safeguards.
Requested amendment. Insert a social and professional transition framework with accessibility by design.
Proposed text for insertion or replacement
Human capability and just transition. Public bodies and publicly funded projects shall assess workforce, professional-responsibility, equality, accessibility and skills impacts before deployment. Employers shall provide role-based AI literacy, consult workers and representatives where required, and retain accountable human professional judgement in regulated services. Education uses shall address child rights, teacher control, academic integrity, assessment validity and age-appropriate data protection. Digital services shall meet applicable accessibility requirements and maintain reasonable non-digital alternatives for essential services. The National AI Skills Observatory shall publish disaggregated outcomes, job-quality effects and skills gaps, while training credentials shall be quality-assured and clearly distinguished from standards, licences and regulatory certifications.
HLTF-27. Create sector legal maps before sector deployment
Strategy reference: Priority-sector roadmaps and Annex C
Comment type: Sector regulation / implementation
Comment and implementation risk. The Strategy’s sector roadmaps often state ‘full alignment’ with EU law without identifying the actual regulatory perimeter, competent regulator, professional decision-maker, evidence standard or additional sector approval. The result is greatest in health, finance, education, employment, maritime, critical infrastructure, justice, law enforcement and public benefits, where AI Act duties coexist with product, safety, data, consumer and professional rules.
Requested amendment. Make a sector legal and standards map a condition to funding and procurement.
Proposed text for insertion or replacement
Sector implementation dossiers. Before funding or procurement in a priority sector, the responsible ministry and competent regulators shall publish a dossier identifying: intended use and AI Act classification; provider/deployer and product-supply-chain roles; applicable sector and professional law; competent authorities; data-access and confidentiality rules; required authorisations and conformity route; fundamental-rights and safety assessment; standards profile; clinical, financial, educational, judicial or operational evidence; human decision authority; incident and complaint routes; liability and insurance; and post-deployment monitoring. At minimum, the dossiers shall address health and medical-device law and EHDS; DORA, MiCA, the DLT Pilot Regime and AML law for finance; education, employment and platform-work law; maritime and product-safety rules; and justice, law-enforcement and biometric safeguards.
HLTF-28. Replace aspirational KPIs with baselines, owners, budgets and independent evaluation
Strategy reference: §§1.5, 2.4, 4.4; Annex F; sector targets
Comment type: Delivery / public finance / evaluation
Comment and implementation risk. Headline targets – including GDP uplift, productivity, 75% adoption and three unicorns – are not accompanied by definitions, baselines, causal models, costs, sensitivity analysis or accountable owners. Adoption is not consistently dated (2030 and 2032). Annex F is described as indicative and may be changed without revising the core Strategy, weakening accountability. Counting deployments can reward low-value or risky use.
Requested amendment. Publish a costed delivery portfolio and independent evaluation protocol before commitments are treated as targets.
Proposed text for insertion or replacement
Delivery, finance and evaluation. Within 120 days, each programme shall have an accountable senior owner, delivery partner, legal basis, baseline, target definition, population, data source, methodology, milestones, dependencies, budget and funding source, procurement route, risk appetite, benefits-realisation plan and stop/scale criteria. Targets shall distinguish adoption from effective, lawful and sustained use. The 75% target and its year shall be reconciled across the document. Macroeconomic and productivity claims shall disclose the model, assumptions, confidence range and attribution limits. An independent evaluator shall publish annual results, incidents, distributional impacts, cost variance and reasons for continuation, modification or termination. Material KPI changes shall require a dated public change notice and governance approval.
Commentary on the Cyprus National AI Strategy 2032
Building an Operational Sovereign AI Ecosystem for Cyprus and Europe
Submitted by Shadgunya Technologies Group
Shadgunya Technologies welcomes the Cyprus National AI Strategy 2032 and strongly supports its ambition to establish Cyprus as a trusted AI hub in the Eastern Mediterranean and a reliable European jurisdiction for AI-enabled services.
The Strategy correctly recognises that AI sovereignty does not require technological isolation. It requires Cyprus to retain meaningful control over critical compute infrastructure, strategic data, models, operational governance, security and skills, while using trusted European and international partnerships to achieve scale. Its proposals for a National AI Infrastructure, federated data architecture, sovereign specialised language models, the Government Innovation Hub, Pharos-CY integration and European AI assurance capabilities provide a strong foundation.
The next step should be to translate these principles into an enforceable national architecture, procurement framework and funded implementation programme.
1. Define AI sovereignty as measurable control
The Strategy should include an operational definition of sovereignty covering six layers:
1. Data sovereignty: Cyprus retains control over the location, access, classification, reuse, retention and deletion of national data.
2. Compute sovereignty: Sensitive workloads can be operated within infrastructure controlled by Cyprus, including protected on-island and offline environments.
3. Model sovereignty: Cyprus can inspect, evaluate, fine-tune, replace and independently operate the models used for critical public functions.
4. Operational sovereignty: Government systems can continue functioning during loss of external connectivity, geopolitical disruption, vendor failure or suspension of a commercial service.
5. Security and supply-chain sovereignty: Cyprus retains encryption-key custody, complete auditability and visibility into software, model and hardware dependencies.
6. Economic and intellectual-property sovereignty: Public investment creates local skills, Cypriot employment, locally anchored IP and exportable European products.
Every critical AI procurement should be assessed against these six dimensions. Any exception should require documented approval from the National AI Authority.
2. Establish a tiered National Sovereign AI Infrastructure
The proposed National AI Infrastructure should not be treated as a single data centre or GPU cluster. It should be a distributed national capability with three security zones:
● European and commercial compute: For non-sensitive research, general experimentation and large-scale training.
● Cyprus Government AI Cloud: For regulated public-sector workloads, operated under Cypriot governance and integrated with the G-Cloud.
● Protected sovereign environments: On-island, offline, air-gapped or edge infrastructure for defence, law enforcement, healthcare, critical infrastructure and other highly sensitive applications.
Large-scale training may use EuroHPC and European AI Factories, while sensitive data processing and mission-critical inference remain under Cypriot control. This would implement the Strategy’s intended balance between sovereign capability and European integration
The infrastructure roadmap should specify:
● Initial and projected GPU capacity.
● Guaranteed compute allocation for government, universities and startups.
● Two-site resilience and disaster recovery.
● Encryption-key custody and privileged-access controls.
● Minimum availability and recovery targets.
● Energy source, cooling, water consumption and power-usage efficiency.
● GPU utilisation, waiting time and cost per workload.
● Hardware and software renewal cycles.
● Procedures for disconnected and degraded operations.
A minimum viable sovereign infrastructure should become operational before 2028, followed by modular expansion through 2032.
3. Correct the sequencing between architecture and procurement
The Strategy proposes launching procurements for six transformational AI solutions within eight months. This creates a risk that applications will be purchased before national standards for data, models, APIs, security and portability have been established.
During the first 180 days, Cyprus should complete:
● A National Sovereign AI Reference Architecture.
● Government-wide data classification and AI workload classification.
● Common API, identity, logging and model-interface standards.
● Standard contractual clauses for AI procurement.
● A national model and application registry.
● Minimum security, testing and lifecycle requirements.
● Vendor exit, data portability and continuity procedures.
Critical AI contracts should require open interfaces, exportable data, reproducible deployment, source-code or model-artifact escrow where appropriate, software and model bills of materials, independent security testing, local knowledge transfer and clearly defined government rights over improvements developed using public data.
This would prevent foreign platform dependence from becoming embedded through early procurements.
4. Build a federated national data fabric—not merely a central warehouse
The Strategy appropriately calls for federated data architecture and sectoral data spaces. This should be expanded into an operational National Data Fabric containing:
● A catalogue of national and sectoral datasets.
● Standard metadata and semantic definitions.
● Data lineage, provenance and quality scoring.
● Purpose-based access and consent controls.
● Privacy-preserving research environments and data clean rooms.
● Federated query and analytics capabilities.
● APIs for authorised government and industry use.
● Immutable audit trails for sensitive access.
● Synthetic and anonymised datasets for innovation.
Cyprus should also create trusted national language and knowledge resources covering Cyprus-relevant legal, administrative, financial, maritime, tourism and public-service terminology. These resources can support specialised multilingual models without requiring Cyprus to train a very large general-purpose model from the beginning.
5. Prioritise specialised sovereign models and reusable components
Cyprus does not need to compete by building the largest foundation model. It can differentiate by developing smaller, efficient and auditable models for regulated European use.
A National AI Model Gateway should allow ministries to use multiple European, open-weight and commercial models through a common governed interface. It should support:
● Specialised language models for Cypriot law and public administration.
● Retrieval from authoritative government sources.
● Multilingual document and speech intelligence.
● Model routing based on security, cost and accuracy.
● Central evaluation and approval.
● On-premise and edge inference.
● Model replacement without rewriting applications.
● Continuous monitoring for accuracy, bias, hallucination and data leakage.
Common capabilities such as document intelligence, identity resolution, multilingual assistants, entity correlation, geospatial analytics and case management should be built once and reused across ministries, consistent with the Strategy’s own “build once, reuse everywhere” principle.
6. Make AI security and assurance a continuous operational function
Compliance should not stop at certification. Cyprus should establish continuous AI assurance covering:
● Prompt-injection and data-exfiltration testing.
● Model poisoning and adversarial manipulation.
● Supply-chain and dependency assessment.
● Red-team testing before production.
● Runtime monitoring and anomaly detection.
● Human override and safe fallback.
● Version control, rollback and decommissioning.
● Incident reporting and coordinated response.
● Periodic re-evaluation after model or data changes.
The proposed European AI Certification Lab should maintain appropriate organisational independence between system developers, operators and assessors. It can become an important European capability by combining EU AI Act readiness with practical cybersecurity and operational-resilience testing.
7. Simplify governance and assign delivery accountability
The Strategy proposes several authorities, councils, committees, observatories, hubs and Centres of Excellence. While each has value, overlapping responsibilities could slow execution.
The National AI Authority should be the single accountable owner of:
● National architecture and technical standards.
● Common platforms.
● Compute allocation.
● Procurement templates.
● Portfolio prioritisation.
● Programme-level budgets.
● Quarterly delivery reporting.
Specialised committees should provide oversight and expert advice without creating additional approval chains. Every flagship programme should have one accountable owner, a defined budget, a delivery timetable and measurable citizen or economic outcomes.
Headline targets such as GDP expansion, the creation of three unicorns and the number of AI professionals should be supplemented with controllable operational indicators: production systems deployed, processing-time reduction, cost avoidance, locally owned IP, export revenue, compute utilisation, public trust, security incidents, SME participation and the percentage of critical workloads that can operate independently.
8. Lessons from Shadgunya’s experience in India
Through its group companies, Pinaca Technologies and Saptang Labs, Shadgunya has worked on sovereign AI, analytics, digital forensics and cybersecurity systems for sensitive government, law-enforcement, defence and national-security environments in India.
Relevant completed and operational experience includes:
● Serving as a technology partner to MARVEL and supporting sensitive law-enforcement and intelligence requirements, including work associated with Maharashtra ATS.
● Providing digital-forensics capabilities to more than 15 Indian agencies, including Income Tax, Customs, the Enforcement Directorate, CBI and NIA.
● Delivering operational social-media monitoring services for India’s Ministry of Electronics and Information Technology.
● Supporting the Indian Cyber Crime Coordination Centre in money-mule and financial-investigation requirements.
● Deploying BlackFence remote-audit capabilities within Indian Army infrastructure.
● Delivering Sovereign AI Products through Indian Army and Indian Navy AI incubation ecosystems.
● Completing Soverign AI based engagements with BSNL and RailTel for network-scale cybersecurity capabilities.
Our experience has produced five important observations:
1. Government AI projects usually fail at the data and workflow layers, not at the model layer. Data preparation, system integration and operational adoption must therefore precede model selection.
2. Sensitive systems require deployment flexibility. On-premise, offline, air-gapped, hybrid-cloud and edge deployment patterns must be part of the original architecture.
3. Auditability is as important as accuracy. Investigative and regulatory systems require provenance, chain of custody, role-based access, human review and reproducible results.
4. Shared capabilities create national scale. Document intelligence, entity correlation, language processing, geospatial analysis and case management should not be procured repeatedly by separate departments.
5. Sovereignty ultimately depends on people. A system is not sovereign if local engineers cannot operate, secure, modify and recover it without continuous external dependence.
9. Proposed Shadgunya contribution in Cyprus
Shadgunya looks forward to adapting these field-tested engineering patterns to Cyprus under European legal, ethical and institutional requirements. We do not propose transferring Indian systems or operating models unchanged. The objective would be to co-develop Cyprus-owned, EU-aligned capabilities with local government, universities, research institutions and industry.
Potential areas of collaboration include:
● Designing the National Sovereign AI Reference Architecture.
● Establishing a secure multi-model government AI platform.
● Developing specialised sovereign models for regulated sectors.
● Creating an AI cybersecurity, red-team and assurance environment.
● Supporting financial-crime, AML and fraud-intelligence applications.
● Building critical-infrastructure, maritime and national-resilience analytics.
● Developing offline and edge AI for sensitive government operations.
● Training Cypriot engineers, AI Officers and security professionals.
● Establishing joint R&D in RISC-V security, sovereign chiplets, SLMs and secure edge AI.
● Creating locally anchored IP and export-ready products from Cyprus.
An initial programme could begin with three lighthouse implementations: a reusable government knowledge and document-intelligence platform, a regulated financial-crime and compliance platform, and an AI security and critical-infrastructure monitoring capability.
Conclusion
Cyprus has an opportunity to become more than a consumer of foreign AI services. It can become a European centre for the design, assurance and export of sovereign AI systems for governments and regulated industries.
The Strategy provides the right direction. Its next iteration should define exactly what Cyprus must control, what it will build nationally, what it will access through Europe, and what every supplier must transfer to the Cypriot ecosystem.
Shadgunya Technologies looks forward to establishing a Cyprus-based sovereign AI engineering, assurance and productisation capability. Our objective is to adapt experience gained from operational government, defence, investigative and cybersecurity projects in India; co-develop these capabilities within Cyprus; ensure alignment with European rights and regulatory frameworks; and use Cyprus as the base from which trusted sovereign AI products can be delivered across Europe.
Commentary on the Cyprus National AI Strategy 2032
Building an Operational Sovereign AI Ecosystem for Cyprus and Europe
Submitted by Shadgunya Technologies Group
Shadgunya Technologies welcomes the Cyprus National AI Strategy 2032 and strongly supports its ambition to establish Cyprus as a trusted AI hub in the Eastern Mediterranean and a reliable European jurisdiction for AI-enabled services.
The Strategy correctly recognises that AI sovereignty does not require technological isolation. It requires Cyprus to retain meaningful control over critical compute infrastructure, strategic data, models, operational governance, security and skills, while using trusted European and international partnerships to achieve scale. Its proposals for a National AI Infrastructure, federated data architecture, sovereign specialised language models, the Government Innovation Hub, Pharos-CY integration and European AI assurance capabilities provide a strong foundation.
The next step should be to translate these principles into an enforceable national architecture, procurement framework and funded implementation programme.
1. Define AI sovereignty as measurable control
The Strategy should include an operational definition of sovereignty covering six layers:
1. Data sovereignty: Cyprus retains control over the location, access, classification, reuse, retention and deletion of national data.
2. Compute sovereignty: Sensitive workloads can be operated within infrastructure controlled by Cyprus, including protected on-island and offline environments.
3. Model sovereignty: Cyprus can inspect, evaluate, fine-tune, replace and independently operate the models used for critical public functions.
4. Operational sovereignty: Government systems can continue functioning during loss of external connectivity, geopolitical disruption, vendor failure or suspension of a commercial service.
5. Security and supply-chain sovereignty: Cyprus retains encryption-key custody, complete auditability and visibility into software, model and hardware dependencies.
6. Economic and intellectual-property sovereignty: Public investment creates local skills, Cypriot employment, locally anchored IP and exportable European products.
Every critical AI procurement should be assessed against these six dimensions. Any exception should require documented approval from the National AI Authority.
2. Establish a tiered National Sovereign AI Infrastructure
The proposed National AI Infrastructure should not be treated as a single data centre or GPU cluster. It should be a distributed national capability with three security zones:
● European and commercial compute: For non-sensitive research, general experimentation and large-scale training.
● Cyprus Government AI Cloud: For regulated public-sector workloads, operated under Cypriot governance and integrated with the G-Cloud.
● Protected sovereign environments: On-island, offline, air-gapped or edge infrastructure for defence, law enforcement, healthcare, critical infrastructure and other highly sensitive applications.
Large-scale training may use EuroHPC and European AI Factories, while sensitive data processing and mission-critical inference remain under Cypriot control. This would implement the Strategy’s intended balance between sovereign capability and European integration
The infrastructure roadmap should specify:
● Initial and projected GPU capacity.
● Guaranteed compute allocation for government, universities and startups.
● Two-site resilience and disaster recovery.
● Encryption-key custody and privileged-access controls.
● Minimum availability and recovery targets.
● Energy source, cooling, water consumption and power-usage efficiency.
● GPU utilisation, waiting time and cost per workload.
● Hardware and software renewal cycles.
● Procedures for disconnected and degraded operations.
A minimum viable sovereign infrastructure should become operational before 2028, followed by modular expansion through 2032.
3. Correct the sequencing between architecture and procurement
The Strategy proposes launching procurements for six transformational AI solutions within eight months. This creates a risk that applications will be purchased before national standards for data, models, APIs, security and portability have been established.
During the first 180 days, Cyprus should complete:
● A National Sovereign AI Reference Architecture.
● Government-wide data classification and AI workload classification.
● Common API, identity, logging and model-interface standards.
● Standard contractual clauses for AI procurement.
● A national model and application registry.
● Minimum security, testing and lifecycle requirements.
● Vendor exit, data portability and continuity procedures.
Critical AI contracts should require open interfaces, exportable data, reproducible deployment, source-code or model-artifact escrow where appropriate, software and model bills of materials, independent security testing, local knowledge transfer and clearly defined government rights over improvements developed using public data.
This would prevent foreign platform dependence from becoming embedded through early procurements.
4. Build a federated national data fabric—not merely a central warehouse
The Strategy appropriately calls for federated data architecture and sectoral data spaces. This should be expanded into an operational National Data Fabric containing:
● A catalogue of national and sectoral datasets.
● Standard metadata and semantic definitions.
● Data lineage, provenance and quality scoring.
● Purpose-based access and consent controls.
● Privacy-preserving research environments and data clean rooms.
● Federated query and analytics capabilities.
● APIs for authorised government and industry use.
● Immutable audit trails for sensitive access.
● Synthetic and anonymised datasets for innovation.
Cyprus should also create trusted national language and knowledge resources covering Cyprus-relevant legal, administrative, financial, maritime, tourism and public-service terminology. These resources can support specialised multilingual models without requiring Cyprus to train a very large general-purpose model from the beginning.
5. Prioritise specialised sovereign models and reusable components
Cyprus does not need to compete by building the largest foundation model. It can differentiate by developing smaller, efficient and auditable models for regulated European use.
A National AI Model Gateway should allow ministries to use multiple European, open-weight and commercial models through a common governed interface. It should support:
● Specialised language models for Cypriot law and public administration.
● Retrieval from authoritative government sources.
● Multilingual document and speech intelligence.
● Model routing based on security, cost and accuracy.
● Central evaluation and approval.
● On-premise and edge inference.
● Model replacement without rewriting applications.
● Continuous monitoring for accuracy, bias, hallucination and data leakage.
Common capabilities such as document intelligence, identity resolution, multilingual assistants, entity correlation, geospatial analytics and case management should be built once and reused across ministries, consistent with the Strategy’s own “build once, reuse everywhere” principle.
6. Make AI security and assurance a continuous operational function
Compliance should not stop at certification. Cyprus should establish continuous AI assurance covering:
● Prompt-injection and data-exfiltration testing.
● Model poisoning and adversarial manipulation.
● Supply-chain and dependency assessment.
● Red-team testing before production.
● Runtime monitoring and anomaly detection.
● Human override and safe fallback.
● Version control, rollback and decommissioning.
● Incident reporting and coordinated response.
● Periodic re-evaluation after model or data changes.
The proposed European AI Certification Lab should maintain appropriate organisational independence between system developers, operators and assessors. It can become an important European capability by combining EU AI Act readiness with practical cybersecurity and operational-resilience testing.
7. Simplify governance and assign delivery accountability
The Strategy proposes several authorities, councils, committees, observatories, hubs and Centres of Excellence. While each has value, overlapping responsibilities could slow execution.
The National AI Authority should be the single accountable owner of:
● National architecture and technical standards.
● Common platforms.
● Compute allocation.
● Procurement templates.
● Portfolio prioritisation.
● Programme-level budgets.
● Quarterly delivery reporting.
Specialised committees should provide oversight and expert advice without creating additional approval chains. Every flagship programme should have one accountable owner, a defined budget, a delivery timetable and measurable citizen or economic outcomes.
Headline targets such as GDP expansion, the creation of three unicorns and the number of AI professionals should be supplemented with controllable operational indicators: production systems deployed, processing-time reduction, cost avoidance, locally owned IP, export revenue, compute utilisation, public trust, security incidents, SME participation and the percentage of critical workloads that can operate independently.
8. Lessons from Shadgunya’s experience in India
Through its group companies, Pinaca Technologies and Saptang Labs, Shadgunya has worked on sovereign AI, analytics, digital forensics and cybersecurity systems for sensitive government, law-enforcement, defence and national-security environments in India.
Relevant completed and operational experience includes:
● Serving as a technology partner to MARVEL and supporting sensitive law-enforcement and intelligence requirements, including work associated with Maharashtra ATS.
● Providing digital-forensics capabilities to more than 15 Indian agencies, including Income Tax, Customs, the Enforcement Directorate, CBI and NIA.
● Delivering operational social-media monitoring services for India’s Ministry of Electronics and Information Technology.
● Supporting the Indian Cyber Crime Coordination Centre in money-mule and financial-investigation requirements.
● Deploying BlackFence remote-audit capabilities within Indian Army infrastructure.
● Delivering Sovereign AI Products through Indian Army and Indian Navy AI incubation ecosystems.
● Completing Soverign AI based engagements with BSNL and RailTel for network-scale cybersecurity capabilities.
Our experience has produced five important observations:
1. Government AI projects usually fail at the data and workflow layers, not at the model layer. Data preparation, system integration and operational adoption must therefore precede model selection.
2. Sensitive systems require deployment flexibility. On-premise, offline, air-gapped, hybrid-cloud and edge deployment patterns must be part of the original architecture.
3. Auditability is as important as accuracy. Investigative and regulatory systems require provenance, chain of custody, role-based access, human review and reproducible results.
4. Shared capabilities create national scale. Document intelligence, entity correlation, language processing, geospatial analysis and case management should not be procured repeatedly by separate departments.
5. Sovereignty ultimately depends on people. A system is not sovereign if local engineers cannot operate, secure, modify and recover it without continuous external dependence.
9. Proposed Shadgunya contribution in Cyprus
Shadgunya looks forward to adapting these field-tested engineering patterns to Cyprus under European legal, ethical and institutional requirements. We do not propose transferring Indian systems or operating models unchanged. The objective would be to co-develop Cyprus-owned, EU-aligned capabilities with local government, universities, research institutions and industry.
Potential areas of collaboration include:
● Designing the National Sovereign AI Reference Architecture.
● Establishing a secure multi-model government AI platform.
● Developing specialised sovereign models for regulated sectors.
● Creating an AI cybersecurity, red-team and assurance environment.
● Supporting financial-crime, AML and fraud-intelligence applications.
● Building critical-infrastructure, maritime and national-resilience analytics.
● Developing offline and edge AI for sensitive government operations.
● Training Cypriot engineers, AI Officers and security professionals.
● Establishing joint R&D in RISC-V security, sovereign chiplets, SLMs and secure edge AI.
● Creating locally anchored IP and export-ready products from Cyprus.
An initial programme could begin with three lighthouse implementations: a reusable government knowledge and document-intelligence platform, a regulated financial-crime and compliance platform, and an AI security and critical-infrastructure monitoring capability.
Conclusion
Cyprus has an opportunity to become more than a consumer of foreign AI services. It can become a European centre for the design, assurance and export of sovereign AI systems for governments and regulated industries.
The Strategy provides the right direction. Its next iteration should define exactly what Cyprus must control, what it will build nationally, what it will access through Europe, and what every supplier must transfer to the Cypriot ecosystem.
Shadgunya Technologies looks forward to establishing a Cyprus-based sovereign AI engineering, assurance and productisation capability. Our objective is to adapt experience gained from operational government, defence, investigative and cybersecurity projects in India; co-develop these capabilities within Cyprus; ensure alignment with European rights and regulatory frameworks; and use Cyprus as the base from which trusted sovereign AI products can be delivered across Europe.
Αρ. Άρθρου:
3.9 Ethics, Trust and Responsible AI
Σχόλιο:
An intersectionally diverse and representative taskforce/cohort of contributors must be ensured with regard to any AI policymaking and governance on a national level.
Αιτιολόγηση σχολίου / Εισήγησης:
The section rightly highlights the importance of ethics, accountability, fairness, transparency, and safeguarding societal values, achieving these goals requires a task force that genuinely reflects all stakeholders and the diversity of Cypriot society. A homogeneous, male-dominated cohort composed primarily of Greek/Greek Cypriots, academic institutions, and private corporations should be avoided. Such narrow governance inevitably skews the values and priorities driving national AI policymaking, which in turn can have considerable political impact on a national level.
A lack of diversity creates policy blind spots and reinforces systemic inequalities that dominant groups can overlook. This issue is particularly critical for AI technologies, which have been proven to exacerbate inequality and further marginalise vulnerable communities across various global contexts, especially when deployed in the public sector, healthcare, recruitment, and law enforcement. In Cyprus, initial research indicates that the most vulnerable groups of the island (such as low-skilled workers, ethnic and sexual minorities, people with disabilities, migrants, and asylum seekers) may face the highest risk of AI-related harm.
Instead, having a cohort that is inclusive in terms of gender, ethnicity, and discipline (including civil society, labour unions, etc) can contribute towards ensuring human rights, fairness and equity, particularly taking the local Cypriot context into consideration. It also ensures that the values and priorities driving AI governance in Cyprus will not be limited to benefitting only a small, dominant section of society. It is recommended that the formation of diverse and inclusive cohorts is embedded directly into the government’s strategic AI planning, and be formally integrated within the Cypriot AI strategy and policymaking infrastructure.
CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE NATIONAL ARTIFICIAL INTELLIGENCE STRATEGY 2032
Submitted by:
Andreas Kazamias
Founder, Platanus Services Ltd, Cyprus
Managing Director EMEA, Liberty IT Consulting Group, Australia
Date: 29 August 2026
Article / Section concerned
National AI Strategy 2032 as a whole, with particular reference to Sections 1.4, 3.2–3.13, 4–5 and Annexes A–F.
Comment / Recommendation
It is encouraging to see Cyprus develop a National AI Strategy and make it available for public consultation. The Deputy Ministry of Research, Innovation and Digital Policy, the Chief Scientist for Research, Innovation and Technology, the National AI Taskforce and all those involved in preparing the Strategy should be congratulated.
The Strategy is ambitious and identifies many of the capabilities Cyprus will require. The principal opportunity before it is finalised is to strengthen the connection between vision, strategic choice and execution.
My principal recommendations are:
1. Sharpen prioritisation.
Cyprus should distinguish between capabilities it must maintain nationally, a limited number of areas where it intends to develop internationally differentiated capability, and capabilities that can be accessed more effectively through European or international partnerships. Possible areas for further assessment include AI assurance and regulatory science, AI for island, climate and resource resilience, and maritime and shipping applications.
2. Define AI sovereignty more practically.
Full technological self-sufficiency is neither realistic nor necessary. For Cyprus, sovereignty should mean retaining control over critical data and functions, sufficient technical knowledge, interoperability, portability, contractual rights and credible alternative suppliers.
Sovereignty should mean retaining the capacity to choose, not restricting the technologies from which Cyprus can choose.
3. Link public-sector AI to measurable benefits.
AI creates additional technology, training, governance and operating costs. Every material public-sector AI programme should therefore identify the capacity expected to be released, the full lifecycle cost and how the benefit will be realised through improved services, redeployment, avoided future recruitment, reduced cost or other measurable public value.
AI deployment is an activity. Realised public value is the outcome.
4. Redesign processes before automating them.
AI should not simply automate existing administrative procedures. Major projects should first simplify processes, eliminate unnecessary approvals and duplicated information requirements, improve data reuse and review workforce responsibilities.
AI should not automate yesterday’s bureaucracy.
5. Make ethics operational.
Ethical principles should be implemented through risk assessment, accountable ownership, testing, documentation, monitoring, incident management and redress. Ethics committees may provide valuable specialist challenge but should not substitute for lifecycle governance. The several ethics-related bodies referred to in the Strategy should also be reconciled and given clear Terms of Reference.
6. Clarify human oversight.
Human-centred AI should preserve accountability and meaningful human intervention in appropriate circumstances, but should not necessarily require a human to repeat every routine AI-supported assessment. Human-in-command does not require human-in-every-transaction.
7. Establish a proportionate private-sector AI governance pathway.
The Strategy provides detailed governance for government but less operational guidance for ordinary enterprises and SMEs. NAICF Comply and AdoptNAICF could provide the basis for a horizontal private-sector framework rather than appearing primarily within Legal Services.
8. Clarify the State’s role in Financial Services and Financial Technology.
Several proposed use cases are principally matters for individual financial institutions. The National Strategy should concentrate on what Cyprus can provide collectively that institutions cannot efficiently provide themselves: coordinated regulatory pathways, appropriate sandboxes, skills, assurance, shared mechanisms where justified, RegTech and SupTech capability and FinTech ecosystem development.
9. Extend data governance beyond access.
The Strategy should address not only who may access public data, but also who may derive models, embeddings, inferred information or other intellectual property from it, on what terms, and who retains the resulting capability.
10. Simplify institutional and sandbox architecture.
Regulatory sandboxes, technical test environments, secure data environments and physical testbeds serve different purposes. Cyprus should avoid creating parallel sector structures where common national capability with specialist participation would suffice. Similarly, Centres of Excellence should strengthen existing universities, research organisations and private capability rather than unnecessarily duplicate them.
11. Clarify specific governance ambiguities.
These include the reporting line and authority of ministry AI Officers; the distinction between development, testing, assurance and formal certification; the relationship between private Legal Services and judicial or public-sector AI; and the status of testing performed by the proposed Industrial Centre of Excellence.
12. Move measurement from indicative to operational.
Annex F is a useful starting point, but each core KPI should define its baseline, target, methodology, source, accountable owner, reporting frequency and intervention threshold. Deployment should be distinguished from measurable outcomes.
13. Apply a consistent evidential standard throughout.
The Education and Human Capital Development section provides a useful example of detailed references and supporting evidence. Material numerical targets, international comparisons and statements of best practice elsewhere in the Strategy should be supported to the same standard.
14. Address additional cross-cutting implementation issues.
The final Strategy should also consider the role of open-source and open-weight AI, contractual allocation of AI procurement risk, retention and traceability of AI-assisted public records, and the risk of excessive concentration around a small number of cloud, model and systems-integration providers.
Justification
Cyprus does not need to lead in every field of Artificial Intelligence. Its size can instead become an advantage if the country is clear about where it intends to lead, where it requires sufficient national capability, and where European and international collaboration will produce better results.
The Strategy already contains much of the necessary foundation. The recommendations above are intended primarily to make the final document more selective, operational and measurable: clearer choices, clearer ownership, realistic sequencing and resources, and a stronger connection between AI investment and demonstrable national benefit.
A full submission has also been provided separately in PDF form. It is structured in three parts: the Main Response, setting out the principal strategic observations and recommendations; a detailed Appendix, containing section- and page-specific observations and recommendations against the National AI Strategy; and a Sources and References section supporting the analysis. This structure allows the broader strategic recommendations to be considered alongside the specific provisions of the Strategy to which they relate.
The PDF should therefore be read together with this summary as the complete contribution to the consultation.
Section 3.11 “Measuring Impact and National KPIs”
Suggestion:
Enhance the existing KPI framework by establishing a comprehensive National AI Performance Scorecard supported by a formal measurement governance structure. Each KPI should be accompanied by a clear definition, baseline value, target trajectory, data source, accountable owner, reporting frequency, calculation methodology, dependencies, and escalation criteria. Furthermore, the scorecard should differentiate between implementation metrics (such as training programmes delivered, AI pilots completed, or digital services enhanced) and impact metrics (such as productivity gains, AI adoption rates, citizen trust, investment attraction, economic contribution, and societal outcomes).
Justification:
The strategy identifies several key dimensions for measuring success, including AI adoption, public sector transformation, talent development, trust, compliance, and economic impact. However, the absence of a structured measurement governance framework may limit the ability to consistently monitor progress and assess the effectiveness of strategic initiatives. A comprehensive performance scorecard would improve transparency, accountability, and evidence-based decision-making by ensuring that all stakeholders operate against a common set of measurable objectives. Clearly defined baselines, ownership responsibilities, and escalation mechanisms would facilitate early identification of underperforming initiatives and support timely corrective actions. This would strengthen the overall governance of the strategy and provide greater confidence that reported progress reflects tangible national outcomes rather than activity levels alone.
Section 3.3, “Governance and Controls”
Suggestion:
Introduce a detailed Roles, Responsibilities and Decision-Making Framework that clearly defines the responsibilities, accountabilities, consultation requirements, and reporting obligations of all governance and delivery stakeholders involved in the implementation of the National AI Strategy. The framework should specify governance interactions across the National AI Authority, the responsible Ministry or Deputy Ministry, the Interministerial AI Council, specialised advisory committees, delivery organisations, regulators, public sector entities, research institutions, local authorities, and private-sector partners.
Justification:
The strategy establishes a robust multi-layer governance structure; however, the practical interaction between the various bodies and stakeholders is not always fully defined. As AI initiatives frequently span multiple policy areas, organisations, and sectors, unclear accountability arrangements may lead to overlapping responsibilities, duplication of effort, delayed decision-making, and implementation challenges. A formal governance and decision-making framework would provide greater clarity regarding ownership of strategic initiatives, funding decisions, risk management, regulatory oversight, and benefit realisation. It would also improve coordination across stakeholders, strengthen accountability for delivery milestones and outcomes, and support more effective escalation and resolution of implementation issues. Ultimately, this would enhance the efficiency and effectiveness of the strategy’s execution and increase the likelihood of achieving its long-term objectives.
Section 3.10.3 “Funding and Renewal Model ”
Suggestion:
Introduce a dedicated, multi-year budget and funding framework for the implementation of the National AI Strategy, including indicative budgets per strategic pillar, funding sources, responsible authorities, and annual allocation mechanisms.
Justification:
While the strategy establishes a clear vision, objectives, and initiatives, it does not provide sufficient visibility regarding the financial resources required to achieve them. Successful implementation of national AI programmes requires sustained investment in digital infrastructure, data platforms, skills development, research and innovation, public sector transformation, cybersecurity, and governance mechanisms. Without a dedicated budget, there is a risk that strategic initiatives will be delayed, scaled back, or implemented inconsistently across government entities. A defined funding framework would enhance accountability, facilitate long-term planning, improve stakeholder confidence, and enable the government to leverage European Union funding programmes and private sector co-investment more effectively.
Section 1.5 “Implementation Timeline and Success Metrics”
Suggestion:
Develop a detailed implementation roadmap with clear milestones, timelines, deliverables, responsible organisations, dependencies, and key performance indicators (KPIs) covering the period up to 2032.
Justification:
The strategy outlines strategic priorities and desired outcomes but would benefit from a more structured execution plan. A roadmap with phased milestones (short-term, medium-term, and long-term) would provide clarity on implementation priorities and sequencing of activities. It would also enable monitoring of progress, facilitate coordination among government entities, academia, and industry, and allow early identification of implementation challenges. Furthermore, measurable milestones would support transparent reporting to stakeholders, strengthen governance, and ensure that progress towards the strategy’s objectives can be objectively assessed and adjusted where necessary. Such an approach aligns with international best practices for national digital and AI strategies and increases the likelihood of achieving the intended outcomes by 2032.
The below 8 recommendations focus on tangible amendments that can strengthen the Strategy’s implementation, accountability, business adoption and investment attractiveness.
1. Costed implementation and investment plan
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.5, 3.10, 3.11 and 5; Annex F.
Σχόλιο / Εισήγηση:
Within 90 days of the Strategy’s adoption, an Implementation and Investment Plan should be approved and published.
For every strategic initiative, the Plan should identify the accountable owner, delivery milestones, budget range, funding source, dependencies, procurement route, measurable KPIs and continuation or exit criteria.
Αιτιολόγηση σχολίου / Εισήγησης:
The Strategy includes several ambitious initiatives and timelines, but many do not yet have an identified owner, budget, funding route or measurable delivery condition.
A single costed implementation portfolio would support effective prioritisation, prevent duplication and enable transparent monitoring of delivery, expenditure and public value.
2. Separation of delivery and statutory supervision
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.4.3, 3.3.1, 3.9.6 and 4.3; Annex A.
Σχόλιο / Εισήγηση:
The final Strategy should clearly distinguish the Strategy owner and delivery office from the competent authorities responsible for market surveillance, conformity assessment, data protection, cybersecurity and sectoral regulation.
No organisation should simultaneously fund or develop AI solutions and provide binding assurance, certification or enforcement concerning those same solutions.
Αιτιολόγηση σχολίου / Εισήγησης:
Clear institutional separation protects regulatory independence, avoids conflicts of interest and provides businesses with greater legal and regulatory certainty.
Innovation support, regulatory sandboxes and pre-compliance guidance are valuable functions, but they should not be confused with statutory supervision, certification or enforcement under the EU AI Act and existing national law.
3. Measurable and consistent national targets
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.5, 2.5 and 3.11; Annex F.
Σχόλιο / Εισήγηση:
For every national KPI, the final Strategy should define:
* The baseline year and value.
* The calculation formula.
* The authoritative data source.
* The accountable owner.
* The reporting frequency.
* The annual target trajectory to 2032.
Any inconsistent adoption percentages or target dates should be reconciled. GDP and productivity estimates should be presented as scenarios until independently validated.
Αιτιολόγηση σχολίου / Εισήγησης:
Targets cannot guide investment or demonstrate impact unless they are clearly and consistently defined.
A public KPI register, updated at least annually, would allow government, businesses and society to distinguish measurable outcomes from activity indicators such as the number of pilots, tools purchased or people attending training.
4. Mandatory data-readiness control gate
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 2.2.2 and 3.2.2; Section 5; Annex B, Control Gates 1 and 2.
Σχόλιο / Εισήγηση:
The Strategy should establish a target publication date for the National Data Policy and the National Data Governance Framework.
Before the procurement, funding or scaling of any public-sector AI use case, the responsible organisation should be required to demonstrate:
* An identified data owner.
* A documented lawful basis.
* Defined data-quality thresholds.
* Data classification, metadata and lineage.
* Retention and access-control requirements.
* Confirmed availability of the required data.
This should become an explicit requirement within the Strategy’s AI use-case control gates.
Αιτιολόγηση σχολίου / Εισήγησης:
AI projects frequently fail or underperform because the required data is unavailable, unreliable, incomplete or not lawfully usable.
A mandatory data-readiness gate would prevent premature procurement, reduce rework and ensure that pilots are selected because they can deliver measurable outcomes—not merely because the technology is available.
5. Investment-compatible definition of AI sovereignty
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.1, 1.2-National Strategic Objectives 6 and 8-1.4.6, 1.6 and 3.7.
Σχόλιο / Εισήγηση:
Expressions such as “controlling all critical layers” and general references to “foreign platforms” should be replaced with objective requirements relating to:
* Effective governance and legal control.
* Security and resilience.
* Legal enforceability.
* Interoperability and portability.
* Operational continuity.
* Supplier choice and exit capability.
Cyprus-only or EU-only hosting requirements should apply only to clearly defined workloads where localisation is required by law or justified by a documented risk assessment.
Suggested wording:
“Cyprus will maintain effective governance, security, resilience and strategic choice across critical AI capabilities through secure architecture, interoperability, enforceable controls and trusted partnerships.”
Αιτιολόγηση σχολίου / Εισήγησης:
For a small and open economy, strategic autonomy should mean retaining effective control and choice while using trusted partnerships to obtain scale and specialist capabilities.
Origin-based preferences or blanket localisation could increase costs, restrict access to innovation and create uncertainty for international investors without necessarily improving security or resilience.
6. Avoidance of duplicative national certification and registration
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 3.9.6 and 4.3; Annex A.
Σχόλιο / Εισήγηση:
The EU AI Act should remain the principal regulatory baseline.
The Strategy should not introduce mandatory national AI certification, universal registration of AI systems or duplicate documentation requirements unless these are supported by a specific legal basis and a demonstrated need.
Compulsory registration should be limited to requirements arising from EU or national law and to proportionate transparency obligations concerning material public-sector AI systems.
Cyprus should instead provide voluntary pre-compliance assessments and coordinated regulatory guidance through a one-stop service.
Αιτιολόγηση σχολίου / Εισήγησης:
Additional national regulatory layers could fragment the EU Single Market, delay product launches and impose disproportionate costs on Cypriot SMEs.
Cyprus can create a genuine competitive advantage through clear guidance, rapid regulatory navigation and credible assurance capabilities rather than through duplicative national obligations.
7. Technology-neutral AI procurement and IP protection
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 1.4.3, 3.4 and 4.2; Annex B and Annex C-Government and Public Sector.
Σχόλιο / Εισήγηση:
The Strategy should provide for the publication of standard AI procurement clauses covering:
* Outcome-based specifications.
* Total lifecycle cost.
* Data and model rights.
* Data and model provenance.
* Security and auditability.
* Model changes and performance drift.
* Interoperability and portability.
* Incident response and business continuity.
* Supplier transition and exit.
Procurement terms should clearly distinguish pre-existing supplier intellectual property from project-created intellectual property.
Model weights, source code, trade secrets and cybersecurity-sensitive information should be protected through proportionate audit and assurance arrangements.
Αιτιολόγηση σχολίου / Εισήγησης:
Public procurement will play an important role in shaping Cyprus’s AI market.
Clear, transparent and technology-neutral requirements would reduce supplier lock-in, allow Cypriot SMEs and international providers to compete fairly and protect legitimate public oversight.
They would also avoid discouraging companies from bringing proprietary technology, investment or research and development activity to Cyprus.
8. One practical pathway for business adoption and investment
Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Sections 3.6, 3.8, 4.4 and 5; Annex C-Entrepreneurship and Innovation.
Σχόλιο / Εισήγηση:
A single, coordinated AI business-adoption and investor pathway should be established, combining:
* AI readiness assessment.
* Regulatory and compliance triage.
* Standard documentation and templates.
* Access to regulatory sandboxes.
* Vouchers or co-funding.
* Access to computing resources.
* Connections with universities and research organisations.
* Talent and relocation guidance.
* Access to public-sector and private-sector pilots.
* Commercialisation and export support.
Each business or investor should have one accountable case manager, supported by published service standards and response times.
The programme should measure productivity gains, exports, investment, skilled employment and successful scaling, not only participation or the number of supported projects.
Αιτιολόγηση σχολίου / Εισήγησης:
Businesses currently risk having to navigate multiple organisations, funding schemes and regulatory processes independently.
A coordinated pathway would reduce adoption barriers for SMEs, improve Cyprus’s investor experience and convert the Strategy’s ecosystem ambition into measurable commercial outcomes.
Comments on the Healthcare and Life Sciences pillar
Submitted by: Denis Losik, PhD Cardiologist, CMO of eMed Support Systems, Limassol registered company
28.08.2026
COVER NOTE
We welcome the Healthcare and Life Sciences pillar, particularly its commitments to data in standards of HL7 FHIR, SNOMED CT, and ICD, as well as its alignment with European Health Data Space principles. We especially support its focus on clinician enablement through accountable AI, intelligent triage and care navigation, and patient-centric service improvement.
The three comments below address one question: how the pillar’s 2032 ambitions for clinician enablement, intelligent triage and care clinical decision support navigation become a dated, measurable program inside the GeSY within the Strategy’s own implementation windows.
Declaration of interest:
eMed Support Systems is a Cyprus-based AI-native platform that provides advanced analytics and clinical decision support for primary care physicians. The platform integrates with healthcare systems via FHIR/HL7 standards as a read-only layer, avoiding disruption to clinical workflows. By applying clinical guideline logic, the platform identifies patients who need attention and recommends next steps to the clinical team, supported by personalized care and population-level analytics.
Annex C, Healthcare and Life Sciences (printed p. 68); Strategic objectives and 2032 target
1) Suggestion/comments:
The Healthcare and Life Sciences pillar could be strengthened by defining a near-term implementation pathway that links the Strategy’s objectives for clinician enablement, intelligent triage and care navigation with current priorities of GeSY.
Recent analysis of the Cypriot health system identifies several areas where this implementation pathway could deliver early measurable value. These include using clinical data from the State Health Services Organization (SHSO) to support AI-enabled data processing, improve chronic disease management, reduce low-value specialist use, improve referral appropriateness, and provide the Health Insurance Organization with better evidence on population health needs, quality of care, and variation in care pathways. Such an approach could support Personal Doctors in making timely decisions and reducing the costs of chronic disease management.
Annex C, Healthcare and Life Sciences (printed p 68) National frameworks and governance
2) Suggestion/comments:
Within the NeHA framework, a dedicated regulatory framework could be developed to address key challenges related to data interoperability and exchange processes. This framework should draw on documents and standards already developed under the EHDS and should be aligned with Regulation (EU) 2025/327 on the European Health Data Space in the Healthcare pillar’s governance provisions, and align the national framework with Article 53 of that Regulation, which sets out the purposes for which electronic health data may be processed for secondary use. Those purposes include scientific research in the health or care sector, including development and innovation activities for products or services and the training, testing and evaluation of algorithms; and the provision of personalized healthcare.
At a later stage, subject to the applicable regulatory and clinical-governance requirements, patient-level decision-support capabilities could be introduced into Personal Doctor workflows to support treatment decisions, investigations, prioritization and indications for specialist referral, while preserving clinical accountability. The sandbox for AI-enabled products should be organized under the NeHA regulation and the data access regulation.
National IT infrastructure should be required to ensure the secure and sovereign use of AI with data from the National Health Data Repository. This should include an evaluation of the computing, storage, interoperability, and security resources needed to process health data at the national level.
The Task Force should also explore potential technical cooperation with cloud and AI infrastructure providers, such as Nebius, Google Cloud, Oracle, Microsoft Azure, and other relevant market participants. These discussions should focus on infrastructure design, data protection, scalability, cost, and compliance with national and EU requirements for the use of health data.
Regulatory classification. Where the pilot advances, at a later stage and subject to clinical-governance requirements, to patient-level decision support in Personal Doctor workflows — treatment decisions, investigations, prioritisation, indications for referral — the Strategy should state that such a system is a medical device under Rule 11 of Annex VIII to Regulation (EU) 2017/745, Class IIa at minimum, requiring a notified body, and that EU AI Act obligations attach on top of that classification rather than in place of it.
Annex C, Healthcare and Life Sciences (printed p 69). Implementation, evidence and compliance
3) Suggestion/comments:
A practical first step of implementation could be a controlled AI-enabled healthcare platform for a pilot in 2026/2027, consistent with the Strategy’s wider implementation timeline for launching pilots within 6-12 months and scaling successful use cases within 12-24 months.
The pilot could focus on a defined high-burden chronic disease population, with cardiovascular disease and diabetes representing a suitable initial use case as one of the largest and most vulnerable patient cohorts. Its purpose would be to test whether routinely available healthcare data from GeSY or SHSO can be used to support:
– systematic identification of population health needs and gaps in care;
– measurement of guideline-based quality indicators and treatment-target attainment, creating a basis for future performance monitoring and Pay-4-Performance frameworks;
– identification of variation in care pathways across providers and patient populations;
– assessment of which patient groups can be appropriately managed in primary care and which meet predefined criteria for further investigation or specialist assessment;
– more timely access to relevant clinical information for healthcare professionals and system planners.
If validated, these capabilities could subsequently be scaled across GeSY to support continuous quality monitoring, stronger primary-care-led chronic disease management, more appropriate use of specialist services, evidence-based resource allocation and the development of performance-based reimbursement models, including Pay-for-Performance.
Justification:
This addition would provide a practical bridge between the Strategy’s 2032 healthcare ambitions and near-term implementation. It would also align the AI Strategy more closely with current priorities of the Cypriot health system. Recent WHO/European Observatory analysis, developed with the support of HIO, identifies underuse of primary care, overuse of outpatient specialist care, weaknesses in the gatekeeping role of Personal Doctors, variation in referral pathways, and limited availability of population-health and performance data. It highlights the need for stronger health information systems, routine population-health analysis, quality and performance indicators, and AI-native decision-support tools for Personal Doctors.
The scale of the utilization challenge is significant. Cyprus residents make approximately 8.7 physician visits per year, including 4.3 outpatient specialist visits, while cardiology alone accounted for approximately 320,000 specialist visits in 2024. Strengthening Personal Doctors and reducing low-value specialist care are therefore directly relevant to both health-system efficiency and quality of care.
A phased implementation pathway could be assessed against clear system-level outcomes, including:
– higher healthcare workforce productivity, through faster analysis of longitudinal patient information and more efficient identification of relevant patient cohorts;
– more appropriate triage and referral, helping Personal Doctors manage suitable patients within primary care while directing higher-risk or complex patients to specialist care;
– educed low-value specialist utilization and unnecessary follow-up, particularly in high-burden chronic disease populations;
– continuous quality and performance monitoring, enabling HIO to measure treatment-target achievements, guideline adherence and agreed clinical KPIs, and providing a stronger knowledge for performance-based reimbursement, Pay-for-Performance and strategic purchasing;
– better chronic disease outcomes and lower downstream utilization, including avoidable specialist care and hospitalizations, to be measured prospectively during pilot and scale-up phases.
Defining these outcomes at the outset would support the Strategy’s broader objective of progressing from isolated AI experimentation toward demonstrable public value. Successful healthcare use cases could subsequently be integrated with the planned Secure National Health Data Repository, in alignment with NeHA regulations for the Digital Healthcare Twin, the Virtual AI Patient Orchestrator, and preparations for EHDS infrastructure. This would help ensure that national investments in data and AI translate into measurable improvements in care delivery, quality, and resource utilization.
The document/strategy is good but in many places it reads generic. To avoid this, it could shorten/omit some of the generics giving emphasis to the local Cypriot dimension.
I would also like to offer the following (five) specific suggestions.
A) Healthcare and Education are missing from the vision part of the document.
B) The emphasis on a human-center perspective in the national vision is commendable but this does not resonate in the document.
Also, we need to remember that at present the technology does not admit the tools that would help companies to easily develop systems that are transparent and compliant by design. Asking for systems that are proactively designed for ethical fairness requires strong regulation from EU which alas is not forthcoming.
The only way to provide some such guarantees is with a strong “human in the loop” element, as the document points out. The strategy could include actions that would support this:
Suggestion: Set up instruments to support a continuous consultation with the stakeholders and the general public before, during and after the development of AI systems.
C) The national strategy needs to focus on the local reality of the reach of the capabilities of Cyprus. AI has not yet proved that it can provide growth and acceleration of productivity, especially in small and medium scale companies. In Cyprus, we cannot sustain infrastructure for large-scale AI and its applications.
Putting the emphasis on the local reality the major related strength of Cyprus is its human resource, particularly within the younger age. AI is an innovation enabler amongst young fresh ideas. Cyprus could set up the aim to create an ever-increasing innovation culture in its society. One suggested action for this the following.
Suggestion: The government can expand its scheme for setting up and funding AI (and other types) start-up companies whose founders are young entrepreneurs.
The scheme should be aggressive in recruiting interest and setting up the startups, with little interference from the funding department, expect to monitor that the companies are taking mentor advice on the business side of start-up companies. The government funding could be generous so that the 2-3 young founders can work full time to set up their innovation and move to the next level of investment funding.
D) Another local advantage is the high-density of medical experts (doctors and others) together researchers in medical informatics and AI. AI can help put together solutions to medical needs that are sensitive to local data that at the same time can form proof of principle solutions for other EU countries.
Suggestion: Create an environment to foster working collaborations targeted on specific local healthcare needs.
E) Regarding AI & Education the challenge is complex. Nevertheless, it is paramount to have a reform in the educational system where emphasis is put on language and dialectic critical thinking skills. AI is turning Natural Language into a Technology Language. For details of our suggestion on this reform see:
https://paideia-news.com/i-texniti-noimosyni-epanaprosdiorizei-tin-ekpaideysi
ΣΧΟΛΙΟ 5 — AI-enabled Built Environment and Permitting Pilot
Αρ. Άρθρου και εδαφίου
Annex C — Government and Public Sector / Priority Sectors · 3.11 Measuring Impact and National KPIs
Σχόλιο / Εισήγηση
Να εξεταστεί η δημιουργία πιλοτικής δράσης “AI-enabled Built Environment and Permitting Pilot”, με αρχική εφαρμογή σε περιορισμένο και ελεγχόμενο πεδίο.
Η πιλοτική δράση προτείνεται να αναπτυχθεί σε τρεις συνδεδεμένους άξονες: α) Planning and Building Permitting, β) Construction Safety and Inspection, και γ) Building Lifecycle and Energy Renovation.
Η εφαρμογή να πραγματοποιηθεί με ανθρώπινη εποπτεία και να αξιολογηθεί βάσει προκαθορισμένων και μετρήσιμων δεικτών, μετά την καταγραφή των αντίστοιχων υφιστάμενων δεδομένων αναφοράς.
Αιτιολόγηση σχολίου / Εισήγησης
Ο τομέας του δομημένου περιβάλλοντος προσφέρει κατάλληλο πεδίο πιλοτικής εφαρμογής ΤΝ, επειδή περιλαμβάνει συγκεκριμένες διοικητικές και τεχνικές διαδικασίες, σημαντικό όγκο δεδομένων και δυνατότητα αντικειμενικής μέτρησης των αποτελεσμάτων.
Στον άξονα της αδειοδότησης μπορούν να αξιολογηθούν εφαρμογές για τον αρχικό έλεγχο πληρότητας, την επεξεργασία εγγράφων και σχεδίων, την υποστήριξη ελέγχου και τη διαχείριση υποθέσεων.
Στον άξονα της κατασκευής και επιθεώρησης μπορούν να εξεταστούν εφαρμογές computer vision, risk analytics, ψηφιακής τεκμηρίωσης, καταγραφής ελαττωμάτων και υποστήριξης θεμάτων ασφάλειας και υγείας.
Στον κύκλο ζωής των κτιρίων μπορούν να εξεταστούν εφαρμογές BIM, digital twins, ενεργειακής απόδοσης, predictive maintenance και υποστήριξης προγραμμάτων ανακαίνισης και ενεργειακής αναβάθμισης.
Πριν από τον καθορισμό ποσοτικών στόχων πρέπει να καταγραφούν τα υφιστάμενα δεδομένα αναφοράς. Στη συνέχεια μπορούν να καθοριστούν δείκτες όπως ο χρόνος αρχικού ελέγχου πληρότητας, ο συνολικός χρόνος διεκπεραίωσης, ο αριθμός επαναλαμβανόμενων παρατηρήσεων, η ακρίβεια των επισημάνσεων του συστήματος, το ποσοστό ανθρώπινης παράκαμψης εισηγήσεων ΤΝ και ο αριθμός επαγγελματιών και τεχνικών που καταρτίστηκαν.
Η πιλοτική εφαρμογή θα επιτρέψει την αξιολόγηση της πραγματικής αποτελεσματικότητας, του κόστους, των κινδύνων και της δυνατότητας επέκτασης πριν από οποιαδήποτε εφαρμογή σε μεγαλύτερη κλίμακα.
ΣΧΟΛΙΟ 4 — ΤΝ στην πολεοδομική και οικοδομική αδειοδότηση / ΙΠΠΟΔΑΜΟΣ
Αρ. Άρθρου και εδαφίου
3.4.1 Priority Areas for Government Adoption · 3.4.2 Prioritization of AI Use Cases · Annex C — Government and Public Sector
Σχόλιο / Εισήγηση
Να συμπεριληφθούν η πολεοδομική και οικοδομική αδειοδότηση, ο οικοδομικός έλεγχος και η επιθεώρηση κατασκευών ως συγκεκριμένη οικογένεια περιπτώσεων χρήσης ΤΝ στον δημόσιο τομέα.
Προτείνεται η ανάπτυξη εφαρμογών AI-assisted decision support, με αξιοποίηση και διασύνδεση με την υφιστάμενη ψηφιακή υποδομή αδειοδότησης, περιλαμβανομένου του συστήματος ΙΠΠΟΔΑΜΟΣ, χωρίς αντικατάσταση της τελικής ανθρώπινης και διοικητικής κρίσης.
Αιτιολόγηση σχολίου / Εισήγησης
Η πολεοδομική και οικοδομική αδειοδότηση αποτελεί διαδικασία με μεγάλο όγκο αιτήσεων, σχεδίων, πιστοποιητικών, τεχνικών εκθέσεων και λοιπών εγγράφων, τα οποία αξιολογούνται έναντι καθορισμένων απαιτήσεων.
Προσφέρεται συνεπώς για εφαρμογές ΤΝ που μπορούν να υποστηρίζουν τον αρχικό έλεγχο πληρότητας του φακέλου, την εξαγωγή δομημένων δεδομένων από αιτήσεις και τεχνικά έγγραφα, την υποβοήθηση ανάγνωσης σχεδίων, τον εντοπισμό αντιφάσεων μεταξύ υποβαλλόμενων στοιχείων, την επισήμανση πιθανών αποκλίσεων προς περαιτέρω έλεγχο και την ταξινόμηση και δρομολόγηση υποθέσεων.
Αντίστοιχες εφαρμογές μπορούν να υποστηρίζουν τον προγραμματισμό επιθεωρήσεων βάσει κινδύνου, την ψηφιακή τεκμηρίωση επιτόπιων ελέγχων και την καταγραφή ελαττωμάτων.
Η ΤΝ πρέπει να λειτουργεί υποστηρικτικά και όχι ως μηχανισμός αυτόματης έκδοσης διοικητικών αποφάσεων. Η τελική διοικητική κρίση πρέπει να παραμένει στην αρμόδια αρχή και η επαγγελματική ευθύνη των αδειούχων μελετητών να διατηρείται για τις μελέτες και πιστοποιήσεις που εμπίπτουν στην αρμοδιότητά τους.
Η εφαρμογή μπορεί να δημιουργήσει μετρήσιμη δημόσια αξία μέσω της μείωσης του διοικητικού φόρτου, της ταχύτερης επεξεργασίας των αιτήσεων και της βελτίωσης της συνέπειας των αρχικών ελέγχων.
Οι δυνατότητες document intelligence, case routing και compliance support που θα αναπτυχθούν μπορούν επιπλέον να επαναχρησιμοποιηθούν σε άλλες διαδικασίες αδειοδότησης του δημόσιου τομέα, σύμφωνα με την αρχή “Build Once, Reuse Everywhere”.
ΣΧΟΛΙΟ 3 — FutureAI CY, ΑνΑΔ και επαγγελματικά προσόντα
Αρ. Άρθρου και εδαφίου
Annex C — Education and Human Capital Development (FutureAI CY) · 3.3.1.7 National AI Skills Observatory
Σχόλιο / Εισήγηση
Να δημιουργηθεί στο FutureAI CY ειδική διαδρομή μάθησης για τις Κατασκευές και το Δομημένο Περιβάλλον, αξιοποιώντας, όπου είναι θεσμικά κατάλληλο, την υφιστάμενη υποδομή επαγγελματικής κατάρτισης και το Σύστημα Επαγγελματικών Προσόντων της ΑνΑΔ.
Να εξεταστεί η αντιστοίχιση και συμπληρωματικότητα των νέων AI micro-credentials με το CyQF/EQF και τα υφιστάμενα επαγγελματικά προσόντα.
Παράλληλα, να συμπεριληφθούν τα επαγγελματικά προφίλ των Κατασκευών και του Δομημένου Περιβάλλοντος στον Cyprus AI Skills Gap Atlas του National AI Skills Observatory.
Αιτιολόγηση σχολίου / Εισήγησης
Ο κατασκευαστικός τομέας αποτελεί κατάλληλο πεδίο εφαρμογής του FutureAI CY λόγω της παρουσίας πολύ μικρών και μικρών επιχειρήσεων, ρυθμιζόμενων επαγγελμάτων και μεγάλου αριθμού διαφορετικών τεχνικών ειδικοτήτων.
Η Κύπρος διαθέτει ήδη οργανωμένη υποδομή επαγγελματικής κατάρτισης και αξιολόγησης επαγγελματικών προσόντων μέσω της ΑνΑΔ, με Κέντρα Επαγγελματικής Κατάρτισης, Κέντρα Αξιολόγησης Επαγγελματικών Προσόντων, εκπαιδευτές και αξιολογητές.
Η αξιοποίηση της υφιστάμενης υποδομής μπορεί να επιταχύνει τη διάχυση δεξιοτήτων ΤΝ στον κατασκευαστικό τομέα και να περιορίσει την ανάγκη δημιουργίας παράλληλων μηχανισμών.
Προτείνεται συνεπώς να εξεταστεί θεσμικά η αντιστοίχιση και συμπληρωματικότητα των νέων micro-credentials με το υφιστάμενο πλαίσιο CyQF/EQF και τα σχετικά επαγγελματικά προσόντα, όπου αυτό είναι εφικτό.
Η προσέγγιση αυτή συνάδει με την αρχή “Build Once, Reuse Everywhere” της Στρατηγικής, εφαρμοζόμενη και στην υφιστάμενη υποδομή ανάπτυξης ανθρώπινου κεφαλαίου.
ΣΧΟΛΙΟ 2 — Εξειδικευμένες δεξιότητες ΤΝ για τις Κατασκευές
Αρ. Άρθρου και εδαφίου
2.5.5 Objective 5: Develop, attract and retain AI-related skills and talent · 3.6.2 Advanced and Sector-Specific Skills
Σχόλιο / Εισήγηση
Να προστεθούν οι Κατασκευές και το Δομημένο Περιβάλλον στους τομείς για τους οποίους προβλέπεται ανάπτυξη εξειδικευμένων και προσαρμοσμένων δεξιοτήτων ΤΝ.
Προτείνεται η ανάπτυξη διακριτών επιπέδων κατάρτισης για: α) μηχανικούς και άλλους επαγγελματίες του δομημένου περιβάλλοντος, και β) τεχνικό, εποπτικό και εργατικό προσωπικό του κατασκευαστικού τομέα.
Αιτιολόγηση σχολίου / Εισήγησης
Η Ενότητα 3.6.2 συνδέει τις απαιτούμενες δεξιότητες ΤΝ με το ειδικό επαγγελματικό και ρυθμιστικό πλαίσιο κάθε τομέα. Οι Κατασκευές αποτελούν έντονα ρυθμιζόμενο επαγγελματικό και τεχνικό περιβάλλον, στο οποίο εμπλέκονται μηχανικοί διαφορετικών κλάδων, μελετητές, εργολήπτες, επιβλέποντες, τεχνικό προσωπικό και δημόσιες αρχές.
Η χρήση ΤΝ μπορεί να αφορά BIM και digital twins, ανάλυση σχεδίων και τεχνικών εγγράφων, επιμετρήσεις, εκτίμηση κόστους, προγραμματισμό έργων, υποστήριξη ελέγχου κανονιστικής συμμόρφωσης, διαχείριση συμβάσεων, επιθεωρήσεις, καταγραφή ελαττωμάτων και θέματα ασφάλειας και υγείας.
Η κατάρτιση δεν πρέπει να περιορίζεται στη χρήση γενικών εργαλείων ΤΝ. Πρέπει να περιλαμβάνει αξιολόγηση της αξιοπιστίας των αποτελεσμάτων, αναγνώριση εσφαλμένων ή μη τεκμηριωμένων αποτελεσμάτων, προστασία προσωπικών και εμπιστευτικών δεδομένων, επαγγελματική ευθύνη και καθορισμό των περιπτώσεων στις οποίες απαιτείται ανθρώπινη επαλήθευση.
Παράλληλα, το εργατικό δυναμικό του κλάδου παρουσιάζει σημαντική διαφοροποίηση ως προς την τυπική εκπαίδευση, τις ψηφιακές δεξιότητες και τη γλωσσική επάρκεια. Απαιτούνται συνεπώς διαφορετικά επίπεδα και μορφές κατάρτισης, προσαρμοσμένα στις πραγματικές ανάγκες κάθε επαγγελματικής ομάδας.
ΣΧΟΛΙΟ 1 — Κατασκευές και Δομημένο Περιβάλλον ως Τομέας Προτεραιότητας
Αρ. Άρθρου και εδαφίου
1.3 Priority Sectors for Leadership · 2.4.1 Priority Sectors for Leadership
Σχόλιο / Εισήγηση
Να προστεθεί ο τομέας Κατασκευών και Δομημένου Περιβάλλοντος (Construction and Built Environment) στους Τομείς Προτεραιότητας της Εθνικής Στρατηγικής για την Τεχνητή Νοημοσύνη.
Σε περίπτωση που διατηρηθεί ο υφιστάμενος αριθμός των οκτώ Τομέων Προτεραιότητας, προτείνεται, ως εναλλακτική, η ρητή αναγνώριση των Κατασκευών και του Δομημένου Περιβάλλοντος ως αυτοτελούς οριζόντιου τομέα εφαρμογής, με καθορισμένο φορέα συντονισμού, συγκεκριμένες δράσεις και μετρήσιμους δείκτες αποτελέσματος.
Αιτιολόγηση σχολίου / Εισήγησης
Ο τομέας των Κατασκευών και του Δομημένου Περιβάλλοντος πρέπει να αξιολογηθεί τόσο βάσει της άμεσης οικονομικής του συνεισφοράς όσο και βάσει της εθνικής και συστημικής του σημασίας. Αποτελεί βασική υποδομή για τη στέγαση, τα δημόσια και ιδιωτικά έργα, τις μεταφορές, την ενεργειακή αναβάθμιση του κτιριακού αποθέματος, την τουριστική ανάπτυξη και σημαντικό μέρος των επενδύσεων της χώρας.
Παράλληλα, παρουσιάζει εκτεταμένο πεδίο αξιοποίησης ΤΝ σε ολόκληρο τον κύκλο ζωής των έργων. Ενδεικτικές εφαρμογές περιλαμβάνουν BIM και digital twins, ανάλυση τεχνικών εγγράφων και σχεδίων, υποστήριξη ελέγχου κανονιστικής συμμόρφωσης, επιμετρήσεις, εκτίμηση κόστους και χρονοδιαγραμμάτων, computer vision για επιθεωρήσεις, εντοπισμό ελαττωμάτων, predictive maintenance και εφαρμογές ασφάλειας και υγείας.
Πρόκειται επίσης για τομέα στον οποίο τα αποτελέσματα εφαρμογών ΤΝ μπορούν να επηρεάζουν τη δομική ασφάλεια, την ποιότητα των κατασκευών, την ασφάλεια και υγεία στην εργασία και την κανονιστική συμμόρφωση. Απαιτείται συνεπώς οργανωμένη υιοθέτηση, με ανθρώπινη εποπτεία, σαφή επαγγελματική ευθύνη και κατάλληλη διακυβέρνηση δεδομένων.
Η συμπερίληψη του τομέα θα συνδέσει τη Στρατηγική με έναν βασικό τομέα υλοποίησης της οικονομικής, στεγαστικής, ενεργειακής και αναπτυξιακής πολιτικής της Δημοκρατίας.
PUBLIC CONSULTATION SUBMISSION
Cyprus National AI Strategy 2032
Consolidated Response
Submitted by: Cyprus Innovation Technologies (CyIT)
Organisation: Not-for-profit technology think tank and enterprise association
Consultation: Cyprus National AI Strategy 2032
Consultation deadline: 31 August 2026.
1. General Position
CyIT welcomes the Cyprus National AI Strategy 2032 and its ambition to strengthen Cyprus’s competitiveness, public-sector modernisation, innovation capacity and responsible AI adoption. CyIT particularly welcomes the Strategy’s emphasis on research and innovation, public-private collaboration, entrepreneurship, skills, testbeds, sectoral adoption and a stronger national technology ecosystem.
CyIT is a not-for-profit technology think tank bringing together expertise from technology, academia, finance, banking and professional services. Having evolved from Cyprus Blockchain Technologies into Cyprus Innovation Technologies, CyIT considers AI within the broader development — and increasing convergence — of emerging technologies.
The comments below are offered constructively. CyIT considers the Strategy an important foundation and identifies a set of areas where greater strategic coherence, costed delivery detail and connection with the wider technology ecosystem would make it more effective and more implementable.
2. Summary of Recommendations
The following fifteen comments are set out in full, with section references, in Section 3 below.
● 1. Anchor the AI Strategy within an updated Digital Strategy. (Section 2.3.2)
● 2. Recognise technology convergence as a horizontal principle. (Sections 2.5, 3.5, 3.7, 3.8)
● 3. Consolidate governance into one coordinating body with clear, costed, time-bound mandates. (Section 3.3.1 and related governance provisions)
● 4. Extend digital readiness and legacy-system planning to systems — not data alone — modernisation, on a phased and costed timeline. (Sections 2.2.1, 2.2.2, 2.2.4, 3.2.5, 3.4.1, 3.7)
● 5. Build a genuine implementation and accountability architecture. (Sections 3.3.1, 3.5, 3.9)
● 6. Publish a costed national AI financing architecture. (Sections 3.3.1, 3.5, 3.7, 3.9, 3.10)
● 7. Recognise established, revenue-generating Cypriot firms as a distinct AI delivery and funding route. (Annex C)
● 8. Name a single approving authority and published criteria for use-case and moonshot selection. (Sections 1.4, 3.3.1, 3.4.2, 3.5)
● 9. Give the innovation ecosystem a structured, continuing implementation role. (Sections 3.3, 3.8, 4)
● 10. Design testbeds to accommodate converged, multi-technology solutions. (Sections 3.8, 3.8.5)
● 11. Extend private-sector support from pilots into funded production implementation. (Section 3.5)
● 12. Add local government as a distinct, resourced delivery layer. (Sections 3.4–3.5 and public-sector implementation generally)
● 13. Broaden AI-literacy programmes to cover emerging-technology convergence. (Section 3.6)
● 14. Extend the KPI framework to measure implementation and ecosystem outcomes. (Section 3.11)
● 15. Build in a periodic horizon-scanning and review mechanism. (Section 3.13)
3. Detailed Comments and Recommendations
Comment 1 — Anchor the AI Strategy within an updated Digital Strategy
Relevant section(s): Section 2.3.2 (Alignment with Digital and Data Strategies); cross-cutting
Issue: The Strategy is intended to guide Cyprus to 2032 but continues to rely partly on the National Digital Strategy 2020–2025. AI depends on wider digital foundations — data, connectivity, cybersecurity, digital identity, cloud/compute infrastructure, interoperability and digital public services — and increasingly interacts with blockchain/DLT, IoT, digital twins, robotics and automation.
Recommendation: Update the overarching Digital Strategy for the period ahead and position the National AI Strategy clearly as a major implementation pillar within it, so AI and other emerging technologies develop within one coherent architecture rather than through separate technology silos.
Comment 2 — Recognise technology convergence as a horizontal principle
Relevant section(s): Sections 2.5, 3.5, 3.7, 3.8; Annexes C–D
Issue: Although the Strategy references digital twins, robotics, autonomous systems and cybersecurity, it treats AI predominantly as a standalone technology. Cyprus already has capability and market experience in blockchain, fintech and distributed technologies that should be leveraged as AI develops, rather than treated as unrelated prior initiatives.
Recommendation: Introduce technology convergence as a horizontal principle. Keep national programmes and use cases technology-neutral, but explicitly consider AI–blockchain/DLT convergence (trusted data and provenance, digital identity, tokenisation, smart contracts, supply chains, machine-to-machine transactions) where it improves outcomes.
Comment 3 — Consolidate governance into one coordinating body with clear, time-bound mandates
Relevant section(s): Section 3.3.1 and related governance provisions (pp.21–27); Sections 3.5, 3.9 (pp.33, 43); Annex A
Issue: The Strategy creates at least ten standing bodies — the National AI Authority, Interministerial AI Council, National AI Taskforce, National AI Infrastructure Committee/Council, National Ethics and Values Committee, National AI Misinformation and Security Council, National AI Skills Observatory, Government Innovation Hub, AI Industrial Centre of Excellence and Cyprus AI Security and Certification Authority — plus AI Officers/Ambassadors and two designated resources in every ministry. No decision-rights map shows where one body’s mandate ends and another’s begins: the infrastructure body is named inconsistently as both “Council” and “Committee,” and Annex A refers to a “National AI Council” that is absent from the governance chapter itself. Neither the Deputy Ministry of Research, Innovation and Digital Policy (named as current implementation owner, p.8) nor the Department of Information Technology Services (not otherwise mentioned in the draft) is given a boundary against the new bodies. No body carries a term, review point or wind-down provision, even though the Strategy itself decommissions underperforming systems and programmes elsewhere (Annex B, Stage 5; §3.11.4).
Recommendation: Consolidate to a single coordinating authority, with specialist functions (ethics, misinformation/security, infrastructure, skills) run as advisory panels sharing one secretariat rather than as standing bodies. Define that authority explicitly against the Deputy Ministry and DITS, stating what it does that they do not. Choose a lifespan: either a fixed term (five years is a reasonable default) with named successor arrangements for each function, or a broader “Modernisation and Innovation” mandate that outlasts the current AI technology cycle. Where a function can be carried by an existing institution, it should be, rather than creating a new standing body for it.
Comment 4 — Extend digital readiness and legacy-system planning to systems — not data alone — modernisation, on a phased and costed timeline
Relevant section(s): Sections 2.2.1, 2.2.2, 2.2.4, 3.2.5, 3.4.1, 3.7 (pp.10–11, 20–21)
Issue: The Strategy correctly diagnoses fragmented, low-interoperability public-sector data and computing infrastructure, and acknowledges that “digital maturity varies across ministries and agencies” (§2.2.4), with some organisations lacking the capability to “identify, procure, and manage AI systems.” However, the stated prerequisite covers data modernisation only (§2.2.2); legacy systems, application modernisation and technical debt are not addressed, even though fragmented data is itself a symptom of an unintegrated application estate. The national data layer and National Intelligent Digital API Fabric (§3.2.5) — though called a prerequisite for the flagship portals — carry no owner, date or budget, and §3.4.1 commits only to “work towards” AI-first procurement principles “by 2032” with no interim milestones.
Recommendation: Widen the stated prerequisite from data modernisation to systems-and-data modernisation, and assess the application estate alongside the data. Give each modernisation instrument, including the data layer and API Fabric, a named owner, budget and completion date. Require a published digital-readiness assessment for each ministry before AI systems are integrated into its legacy estate, and express at least one modernisation milestone as a gate on the adoption target so sequencing is visible and testable, rather than relying on the 2032 horizon alone.
Comment 5 — Build a genuine implementation and accountability architecture
Relevant section(s): Sections 3.3.1, 3.5, 3.9
Issue: The Strategy sets out governance bodies, timelines and KPIs, but this falls short of delivery discipline. It does not yet translate the 2032 vision into programme-by-programme ownership, annual milestones, inter-programme dependencies, decision rights, a benefits-realisation methodology, or stated consequences when a programme falls behind. Without these elements, the 16 flagship programmes and 6 moonshots referenced in §3.5 risk remaining a strategic framework rather than a delivery programme.
Recommendation: Require, for each moonshot programme once selected, a one-page delivery charter naming an accountable senior owner, annual (not only 2032) milestones, a dependency map against other programmes and infrastructure, a benefits-realisation plan with measurable indicators, and defined remedies for slippage. Review progress against these implementation commitments, not only against final 2032 targets.
Comment 6 — Publish a costed national AI financing architecture
Relevant section(s): Sections 3.3.1, 3.5, 3.7, 3.9, 3.10
Issue: The Strategy commits repeatedly to expenditure without figures. Section 3.3.1 states only that “budget allocations will be aligned with the strategic performance goals agreed between the Ministry of Finance and the Deputy Ministry,” with no per-programme costing; Section 3.10 promises “multi-year investment with clear ROI tracking” without numbers; and Section 3.7 commits to a National AI Infrastructure described as a “strategic national asset” with no costed funding plan attached. This makes it difficult to assess whether the Strategy’s ambitions, including its 75% adoption target, are financially achievable.
Recommendation: Publish an indicative national AI financing architecture for 2026–2032, itemising expected investment and the expected return or outcome metric by source — government funding, EU funding, private investment, R&D support, SME adoption subsidies, compute credits, procurement expenditure and venture/scale-up capital — and cross-reference it explicitly to the 75% adoption target so funding and ambition can be assessed together. Attach indicative cost ranges, funding sources, milestones and review dates to each major commitment, particularly the National AI Infrastructure.
Comment 7 — Recognise established, revenue-generating Cypriot firms as a distinct AI delivery and funding route
Relevant section(s): Annex C (pp.60–87, including p.73, p.86); Sections 3.3.1 (p.26), 3.3.2 (p.27), 5 (p.50)
Issue: The Strategy builds two funding and delivery routes well — public-sector adoption (institutional AI strategies, delivery bodies, dated procurements) and the startup/spin-off pipeline (incubation, venture co-investment, university commercialisation). Established Cypriot firms past the startup stage but below corporate scale — already profitable and already holding sector knowledge in shipping, law, hospitality or finance — are the most likely source of exportable Cypriot AI products, yet they are named only once, in passing (“targeting the development of existing SMEs and MEs,” p.50). The nearest instrument, the AI Sovereign Investment Matching Fund, is shaped for equity rounds (25% pre-seed/seed, 75% Series A/B; conditions written for “any startup receiving government support,” p.86) and does not fit a profitable firm that is not raising a round.
Recommendation: Name established AI-building/selling firms as a distinct route alongside the public-sector and startup routes, with its own logic from product development through capital to first customer and export. Clarify what “ME” means (align to the EU small mid-cap definition if intended) and ensure profitable firms not raising equity can access support. Prioritise funding for defined products with an identified buyer and a credible revenue path over studies and assessments, and consider models (e.g. the Israel Innovation Authority) where support is repaid from resulting revenue. Measure products reaching market, revenue and export revenue in Annex F, and give the AI Industrial Centre of Excellence a clear establishment date, budget and access criteria.
Comment 8 — Name a single approving authority and published criteria for use-case and moonshot selection
Relevant section(s): Sections 1.4, 3.3.1, 3.4.2, 3.5; Annexes B–C (Figures 5–12)
Issue: Annex C lists “Recommended Use Cases, Moonshots and KPIs to be considered” for each of the eight priority sectors without making clear whether these are illustrative or committed. Section 3.5 states 16 flagship programmes will be assessed and narrowed to 6 moonshots by the National AI Authority “following stakeholder consultation” — without defining which stakeholders, what criteria, what weighting, or a decision date. At least three parallel, unreconciled approval pathways exist: the National AI Authority’s 16-to-6 selection; the Government Innovation Hub’s separate validation gate (§1.4.3); and ministries’ independent authority to identify and prioritise their own use cases (§3.3.1) through mandatory Applied AI Strategies. Annex B’s control gates add further checkpoints without specifying gate criteria or committee composition. The Strategy itself warns against “AI theatre” — “many experiments, little impact” (§1.4) — the likely outcome of naming aspirational use cases without a single approving authority.
Recommendation: Name a single final approving authority for moonshot selection, publish selection criteria and their weighting, and fix a decision date for the 16-to-6 narrowing. Amend Annex B to name the approving body and pass/fail criteria for each control gate. Require ministry-level use cases selected outside the moonshot list to pass through the same Government Innovation Hub validation gate. Require multidisciplinary validation (public bodies, industry, academia, ecosystem) before major investment is committed, and review the use-case portfolio periodically.
Comment 9 — Give the innovation ecosystem a structured, continuing implementation role
Relevant section(s): Sections 3.3, 3.8, 4
Issue: The Strategy’s emphasis on government–industry–academia collaboration is welcome, but effective implementation requires continuing engagement beyond consultation and strategy-development. Cyprus already has technology associations, not-for-profit organisations, innovation communities, professional bodies, startups and enterprises able to contribute market knowledge, identify use cases and support technology literacy.
Recommendation: Provide a structured mechanism for continuing ecosystem participation during implementation, using existing ecosystem organisations rather than creating new public structures for functions they can already perform. CyIT would be willing to contribute within its areas of expertise and through its multidisciplinary membership.
Comment 10 — Design testbeds to accommodate converged, multi-technology solutions
Relevant section(s): Sections 3.8, 3.8.5; Annex D
Issue: CyIT strongly supports the proposed testbeds, sandboxes and experimentation environments, but real-world innovation increasingly involves systems combining AI with other technologies; environments designed too narrowly around AI alone may limit experimentation and commercialisation.
Recommendation: Design national testbeds to accommodate integrated solutions combining AI with blockchain/DLT, IoT, digital identity, digital twins, robotics, autonomous systems and cybersecurity where appropriate. Encourage a “pilot before scale” approach with measurable outcomes, and share non-confidential lessons from successful and unsuccessful pilots across the ecosystem.
Comment 11 — Extend private-sector support from pilots into funded production implementation
Relevant section(s): Section 3.5 (Supporting SMEs; NAICF Comply / AdoptNAICF)
Issue: The private-sector support architecture is built almost entirely around SME adoption assistance, and specifically around preparatory stages: AdoptNAICF’s subsidy is gated behind NAICF Comply’s baseline AI Act governance requirement, and industry adoption is described as “not mandatory… however, highly recommended.” This funds compliance groundwork, studies, assessments and pilots, without a stated mechanism for funding the point at which a company integrates a system into production and runs it. The adoption challenge is also not limited to SMEs — larger Cyprus enterprises face similar implementation, integration, skills and infrastructure barriers, with no distinct support track outside the SME band.
Recommendation: Restructure AdoptNAICF, or add a parallel instrument, to fund the ongoing running and integration costs of production AI implementations, not only studies and pilots. Introduce a distinct implementation-support track for enterprises outside the SME band, naming specific enablers — production-grade sandbox access, technical integration assistance, a delivery-support function — separate from NAICF Comply’s compliance guidance.
Comment 12 — Add local government as a distinct, resourced delivery layer
Relevant section(s): Sections 3.4–3.5 and public-sector implementation generally
Issue: The Strategy focuses on central government and the eight priority economic sectors. Municipalities, however, deliver many services citizens experience directly — permits, waste management, planning, local infrastructure, traffic, environmental management and local-language services — and are not treated as a distinct delivery stream.
Recommendation: Add local government as a named, distinct delivery stream within the public-sector programme, with its own use cases, resourcing pathway and digital-readiness assessment — paralleling the ministry-level readiness work in Comment 4 — rather than addressing municipalities only implicitly through national programmes.
Comment 13 — Broaden AI-literacy programmes to cover emerging-technology convergence
Relevant section(s): Section 3.6 (Talent, Skills and Workforce Transformation)
Issue: CyIT strongly supports the emphasis on AI literacy and workforce transformation. However, executives, professionals, public officials and citizens increasingly need to understand AI within the wider technology environment — data, cybersecurity, cloud infrastructure, digital identity — with which it interacts.
Recommendation: Add an emerging-technologies and technology-convergence dimension to AI-literacy programmes, particularly for policymakers, business leaders, professionals, SMEs and public-sector decision-makers, to support more informed technology selection and reduce both under-adoption and hype-driven adoption.
Comment 14 — Extend the KPI framework to measure implementation and ecosystem outcomes
Relevant section(s): Section 3.11; Annex F
Issue: The Strategy contains extensive KPIs, but the ultimate test of a national technology strategy is successful implementation and a sustainable innovation ecosystem — whether pilots reach production, research is commercialised, SMEs and startups gain access to infrastructure and markets, and Cyprus develops internationally scalable solutions.
Recommendation: Add measurable implementation and ecosystem indicators to the KPI framework alongside adoption metrics: pilot scale-up, industry–academia collaboration, SME/startup participation, private investment mobilised, commercialisation outcomes and internationally scalable solutions.
Comment 15 — Build in a periodic horizon-scanning and review mechanism
Relevant section(s): Section 3.13 (Risk Management, Resilience and Adaptation); cross-cutting
Issue: A Strategy extending to 2032 must recognise that technologies, deployment models and significant use cases will emerge that cannot be fully predicted in 2026 — the pace of change in generative and agentic AI already demonstrates this.
Recommendation: Include a periodic horizon-scanning and review mechanism covering material developments in AI and other emerging technologies (including their convergence), new use cases, risks, infrastructure requirements and international developments, drawing on government, academia, industry and the wider ecosystem, capable of informing adjustments to priorities and investment during implementation.
4. Sector-Specific Observations
Two further, narrower points from the underlying review drafts are recorded here for completeness, as they concern specific sector proposals rather than cross-cutting Strategy design.
Comment 16 — Broaden the Financial Services / FinTech use-case programme
Relevant section(s): Financial Services and Financial Technology priority sector
Issue: The existing focus on AML, fraud detection, intelligent insurance, AI-augmented advisory and regulatory reporting is useful, but understates how quickly the sector is converging with tokenised assets, blockchain-based market infrastructure, digital identity, programmable payments, RegTech/SupTech and agentic financial services — an area where Cyprus already has deep professional, regulatory and market capability.
Recommendation: Expand the financial-services use-case programme into an AI, FinTech and Digital Finance Innovation Track capable of considering convergent technology models.
Comment 17 — Reconsider the role of blockchain in AIREG as part of a wider innovation programme
Relevant section(s): Legal Services – AIREG
Issue: CyIT welcomes blockchain’s appearance in the Strategy through the AIREG proposal, but no technology should be selected solely because it appears innovative, and blockchain should not be confined to a single registry use case without a feasibility assessment against alternative architectures.
Recommendation: Reframe AIREG as one candidate use case within a broader, technology-neutral Trusted AI and Digital Provenance Programme, subject to a multidisciplinary feasibility and pilot process considering interoperability, data/metadata requirements, privacy, governance, digital identity, cybersecurity and evidentiary requirements — so that lessons generated can support other sectors.
5. Standards and Regulatory Coherence
CyIT recognises that implementation of the National AI Strategy will take place within the framework of the EU Artificial Intelligence Act, the national legislation being developed for its implementation, and the wider European regulatory environment.
CyIT also recognises the important role of standards and of the Cyprus Organisation for Standardisation (CYS) in supporting interoperability, security, trustworthy AI and market access. These matters should be appropriately reflected in the final Strategy; CyIT does not consider it necessary in this submission to duplicate the detailed legal or standardisation analysis more appropriately addressed by competent institutions and specialist stakeholders.
From CyIT’s perspective, the principal objective is to ensure that the regulatory and standards environment provides certainty and trust while remaining capable of supporting responsible experimentation, innovation, commercialisation and scaling.
6. Conclusion
Cyprus’s National AI Strategy 2032 sets an ambitious and largely well-founded direction, but its biggest risks are structural: it stacks new institutions, funding commitments and use-case selections without a single coordinating authority, a costed budget, or a clear decision-rights map, and it leans on the National Digital Strategy 2020–2025 rather than an updated digital foundation. Fixing these — one accountable governance body, a published financing architecture, and a clearer path from proposed use case to funded delivery — would do more for credibility than any single new programme.
Beyond that, implementation readiness needs more attention than the draft currently gives it: legacy-system and digital-maturity gaps across ministries aren’t sequenced or costed, the moonshot/use-case approval process runs through at least three overlapping pathways, and established Cypriot firms sit in a funding gap between the startup and public-sector tracks the Strategy does address.
Finally, the Strategy would be strengthened by treating AI as one part of a wider, converging technology landscape — recognising local government, the private sector beyond pilots, and the broader innovation ecosystem as ongoing implementation partners, broadening technology literacy accordingly, and building in periodic review so the Strategy can adapt as the technology and its use cases evolve through 2032.
1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο: Section 3.8.1 and Annex D, Focus Area 5 (Next-Generation Wireless Telecommunications, printed p. 89); Section 2.2.1 (printed p. 9); Section 3.8.5 (National Testbeds, printed p. 41).
Σχόλιο / Εισήγηση: Focus Area 5 should be given the same institutional treatment as the other focus areas: a named delivery mechanism, an associated testbed or experimentation facility, and at least one indicator in the Annex F framework. Specifically, add an advanced connectivity and network-AI testbed to the national testbed programme in §3.8.5, and state which body is responsible for the focus area.
Αιτιολόγηση σχολίου / Εισήγησης: The six focus areas are presented as equivalent, but their institutional backing is not. Autonomous Systems is tied to a physical test park and to the maritime pillar; Healthcare to the National Health Data Repository; Security, Defence and Space to a dedicated Centre of Excellence. Next-Generation Wireless has three bullet points, no host, no facility and no indicator, and telecommunications does not appear among the eight priority sectors. Section 2.2.1 treats connectivity as an achieved condition (95.5% FTTH, 100% 5G coverage), which explains the omission but does not justify it: the Strategy elsewhere requires real-time AI services, edge deployment and national interoperability, all of which are network capabilities that do not exist today and will not arrive without directed investment. A research priority with no delivery mechanism attached will not attract funding and will not be measured.
1. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 3.8.1 and Annex D, Focus Area 5 (Next-Generation Wireless Telecommunications, printed p. 89); Section 2.2.1 (printed p. 9); Section 3.8.5 (National Testbeds, printed p. 41).
Σχόλιο / Εισήγηση
Focus Area 5 should be given the same institutional treatment as the other focus areas: a named delivery mechanism, an associated testbed or experimentation facility, and at least one indicator in the Annex F framework. Specifically, add an advanced connectivity and network-AI testbed to the national testbed programme in §3.8.5, and state which body is responsible for the focus area.
Αιτιολόγηση σχολίου / Εισήγησης
The six focus areas are presented as equivalent, but their institutional backing is not. Autonomous Systems is tied to a physical test park and to the maritime pillar; Healthcare to the National Health Data Repository; Security, Defence and Space to a dedicated Centre of Excellence. Next-Generation Wireless has three bullet points, no host, no facility and no indicator, and telecommunications does not appear among the eight priority sectors. Section 2.2.1 treats connectivity as an achieved condition (95.5% FTTH, 100% 5G coverage), which explains the omission but does not justify it: the Strategy elsewhere requires real-time AI services, edge deployment and national interoperability, all of which are network capabilities that do not exist today and will not arrive without directed investment. A research priority with no delivery mechanism attached will not attract funding and will not be measured.
2. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 1.4.3 (printed p. 4); Section 3.3.1, Innovation and Development Bodies (printed p. 22); Section 3.3.1, National AI Industrial Centre of Excellence (printed p. 26); Section 3.4 (printed p. 31); Annex C, Government and Public Sector (printed p. 63); Section 2.2.3 (printed p. 10).
Σχόλιο / Εισήγηση
The Strategy should state the legal form and ownership model of each proposed Centre of Excellence, and should state the intended relationship between the new national Centres and the seven Centres of Excellence already operating in Cyprus, i.e whether the new Centres are to be hosted by, built upon, or established independently of them. A single consistent name should be adopted for each Centre throughout the document.
Αιτιολόγηση σχολίου / Εισήγησης
The Industrial Centre of Excellence is described in four incompatible ways: as an entity “dedicated to the private sector” (p. 4); as a body within the national governance structure (p. 22); as an entity that “reports to the National AI Authority” (p. 31); and as “a publicly supported private entity” (p. 63). These imply different procurement routes, different state aid treatment, different IP arrangements and different accountability lines. The question cannot be deferred to implementation, because the choice determines who may host or participate before any host is selected. Separately, §2.2.3 records that Cyprus already has seven Centres of Excellence, and no subsequent text connects them to the new bodies. Establishing national Centres alongside existing ones without stating the relationship risks precisely the duplication of public investment that §3.7 identifies as a structural weakness. The Centre is also named five different ways across the document, which should be corrected in the final text.
3. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 3.3.1, National AI Industrial Centre of Excellence (printed p. 26); Annex C, Financial Services (printed p. 66); Section 3.9.6 (printed p. 43); Section 4.3, NAICF (printed p. 49); Annex A, EU AI Act (printed p. 53).
Σχόλιο / Εισήγηση
The Strategy should separate the development and assurance functions currently assigned to the Industrial Centre of Excellence. A body providing “development and engineering” across priority sectors should not also validate models against EU AI Act requirements before commercial deployment. The Strategy should further clarify the division of responsibility between the Centre, NAICF, the national certification registry, the “Cyprus AI Security & Certification Authority” named at p. 43, and the Competent Authorities already designated under the AI Act.
Αιτιολόγηση σχολίου / Εισήγησης
Page 26 tasks the Centre with resources, development and engineering; page 66 tasks the same Centre with validating models against EU AI Act requirements before commercial deployment and with producing compliance blueprints. An organisation cannot credibly assess systems it has helped build, and market participants that compete with the Centre’s engineering work will not accept its conformity judgements. The confusion is compounded by the number of assurance actors: NAICF, the registry, the Certification Authority (which appears once and does not appear in the governance structure at §3.3.) and the Communications Commissioner and Data Protection Commissioner, who hold the statutory role under the Act.
4. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 3.3.1, National AI Cybersecurity Centre of Excellence (printed p. 26); Section 5, item 3 (printed p. 51); Section 3.3.1.6, National AI Misinformation and Security Council (printed p. 24); Section 4.2.1 (printed p. 49).
Σχόλιο / Εισήγηση
The two descriptions of the Cybersecurity Centre of Excellence should be reconciled, and the boundary between the Centre and the National AI Misinformation and Security Council should be drawn explicitly. The final text should also state on what terms international partners participate, in particular the ownership of intellectual property arising from jointly developed work and the treatment of results produced by Cypriot research institutions.
Αιτιολόγηση σχολίου / Εισήγησης
Page 26 describes a centre bringing together industry, academia and public institutions around frontier security research and practical standards. Page 51 describes a body operating “in partnership with leading global players” and developing “AI cyberwarfare professionals.” These are different institutions with different governance requirements, different security classifications and different funding models. The misinformation and disinformation remit at p. 51 also duplicates the mandate given to the Misinformation and Security Council at p. 24. On the partnership question, an anchor-partner model in which an international participant leads the technical work and domestic institutions supply personnel produces a centre that is located in Cyprus without building national capability(the outcome Objective 8 is intended to prevent!). Stating the IP and knowledge-transfer terms in the Strategy is what makes Objective 8 operative rather than aspirational.
5. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 1.2 (printed p. 3); Section 1.4.3, “AI Centres of Excellence” (printed p. 4); Section 1.3 (printed p. 3); Section 3.3.1 (printed pp. 22, 26); Section 5, item 3 (printed p. 51); Annex C, Maritime (printed p. 83).
Σχόλιο / Εισήγηση
Reconcile the plural “AI Centres of Excellence dedicated to the private sector” at §1.4.3 with the two horizontal Centres actually defined at §3.3.1. Either state that sector-specific Centres will be established and identify which sectors, or amend §1.4.3 to describe a single horizontal Industrial Centre and drop the “dedicated to the private sector” characterisation, which does not match a body that also reports to the National AI Authority and supports ministries directly.
The plural framing is unsupported. §1.2 (p. 3) describes CoEs as “industry-oriented”; §1.4.3 (p. 4) describes them as “dedicated to the private sector to accelerate use case adoption.” But the two actually defined are horizontal layers, not sector bodies, and the mapping onto the eight sectors is incoherent: The Industrial CoE is assigned to government (p. 63), financial services (p. 66), tourism (pp. 34, 73), legal services (p. 74), and at p. 51 to “GovTech, FinTech, ShipTech, tourism, and HealthTech.” That is one body for at least six of the eight sectors. The Cybersecurity CoE maps to no priority sector at all. It corresponds to Annex D Focus Area 4 (Security, Defence and Space), which is a research focus area and not a priority sector. Shipping and Maritime, the sector where Cyprus has its strongest global position, gets only a conditional: it “may be supported by a Centre of Excellence” (p. 83). Education, and Entrepreneurship and Innovation, get no CoE reference.
Αιτιολόγηση σχολίου / Εισήγησης
As drafted, one Industrial Centre of Excellence is expected to provide engineering, adoption support, governance guidance, compliance blueprints and sandbox validation across at least six of the eight priority sectors, each with distinct regulators, data regimes, professional bodies and technical requirements. No single organisation can hold credible domain depth across shipping, healthcare, legal services, tourism, finance and public administration simultaneously, and a body that attempts it will deliver generic advisory output — which is the “AI theatre” outcome the Strategy identifies as an execution risk at §1.4. Conversely, the Cybersecurity Centre is mapped to no priority sector, so the two Centres between them are simultaneously over-extended and unaligned to the sector structure the Strategy is organised around. Maritime is the clearest case: it is the sector with the strongest existing international position and the only one where a Centre is proposed conditionally.
6. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 3.3.1, National AI Cybersecurity Centre of Excellence (printed p. 26); Section 1.1, Fundamental Principles (printed p. 2); Section 3.3.1.5 (printed p. 24); Section 3.9 and 3.13.3 (printed pp. 43, 46); Annex D, Focus Areas 4 and 6 (printed pp. 89–90); Section 5, item 3 (printed p. 51).
Σχόλιο / Εισήγηση
Rename National AI Cybersecurity Centre of Excellence to “National Centre of Excellence for Trustworthy and Secure AI”, and extend its mandate beyond cybersecurity to cover the full technical assurance of AI systems: adversarial robustness, model evaluation and benchmarking, red-teaming, bias and fairness auditing, explainability methods, privacy-preserving learning, and the development of national testing methodologies for high-risk systems under the EU AI Act. Cybersecurity remains within the mandate; it becomes one dimension of trustworthiness rather than the whole of it.
Αιτιολόγηση σχολίου / Εισήγησης
The Fundamental Principles at §1.1 commit Cyprus to security and resilience, fairness and non-discrimination, transparency and human oversight. Of these, only security is assigned to a body with technical capability. The National Ethics and Values Committee is advisory and described in a single sentence; NAICF addresses compliance and certification, which is a documentation function rather than a testing one. No body in the Strategy is responsible for determining whether a deployed system is actually robust, actually unbiased, or actually explainable. That is a technical question requiring laboratory capability, not an ethical or administrative one, and without it the AI Act conformity assessments the Strategy anticipates will rest on vendor self-declaration. Extending the Centre’s scope is also methodologically coherent: adversarial robustness testing, model evaluation, red-teaming and fairness auditing share techniques, tooling and expertise. Establishing a Centre that covers only the security subset and leaving the remainder unassigned would fragment a single technical discipline across bodies that do not exist. The narrower title also mismatches the mandate already given at p. 26, which includes securing AI systems themselves, which is an activity that is inseparable from evaluating them.
7. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 2.2.2, final paragraph (printed p. 10); Section 1.5 (printed p. 6); Section 3.2.2 (printed p. 20); Section 5, items 1 and 6 (printed pp. 50, 52); Annex B, Control Gates 1 and 2 (printed pp. 58–59).
Σχόλιο / Εισήγηση
The characterisation of the National Data Policy and the National Data Governance Framework as a prerequisite rather than a parallel activity is correct and should be retained. It should also be made operative: state a target publication date for both instruments, sequence the implementation timeline at §1.5 and the immediate steps at §5 against that date, and add an explicit data-readiness condition at Annex B Control Gate 1 or 2, so that a use case cannot pass the gate without demonstrating that the data it depends on is governed, documented and lawfully available under the national framework.
Αιτιολόγηση σχολίου / Εισήγησης
Section 2.2.2 correctly identifies the sequencing that most national AI programmes get wrong. As drafted, however, the Strategy states the dependency in Chapter 2 and does not observe it thereafter. No delivery date is given for either instrument, while §1.5 places infrastructure deployment and pilot launches at 6 to 12 months and §5 commits to launching procurements for six transformational solutions within eight months. If the data framework is genuinely a prerequisite, then those milestones are conditional on a deliverable with no date, and the timeline cannot be relied upon. If it is not a prerequisite, the paragraph at §2.2.2 should be amended. Attaching the requirement to a control gate is the mechanism that makes the stated principle binding, since it is at the gate that a project either has governed data or does not.
8. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 3.7 and 3.7.2 (printed pp. 38–39); Section 3.3.1.4, National AI Infrastructure Committee (printed p. 24).
Σχόλιο / Εισήγηση
The Strategy should specify the composition of the National AI Infrastructure Committee, including representation from universities and research organisations, and should clarify the intended treatment of existing publicly funded institutional research computing, whether it is to be consolidated, federated, or left in place with coordinated access. My opinion is that any infrastructure already in place should remain so, and there should be coordinated access to all, if needed and possible. The HPC at UCy has a research and Educational purpose, which cannot be ignored and cancelled. The body is called a Council at §3.3.1 and a Committee at §3.3.1.4; one term should be used.
Αιτιολόγηση σχολίου / Εισήγησης
Section 3.7.2 states that the National AI Infrastructure should not belong to “any individual ministry, university, research organisation, or company,” and §3.7 opens by characterising existing institutional resources as fragmented and duplicative. Read together, these imply a consolidation of resources that were competitively won and are currently committed to funded research programmes with contractual obligations to European funders. Consolidation and federation are both defensible, but they have very different consequences for existing projects, and the Strategy does not say which is intended. Section 3.7.2 also assigns oversight to “an appropriate governance framework representing government, academia, research organisations, and industry,” while §3.3.1.4 defines the Committee’s functions without defining its membership. Since that body will set annual compute priorities, its composition determines whether the stated representation is real.
9. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 5, item 2 (printed p. 50); Section 4.4, Incentive Mechanisms and AI ERC Bridge (printed p. 50); Annex C, Legal Services (printed p. 75); Annex F (printed p. 93).
Σχόλιο / Εισήγηση
The National AI Research Fund and the AI ERC Bridge should be given an administering body, an indicative multi-annual allocation and a first-call date. The Strategy should state the role of the Research and Innovation Foundation in the national AI research portfolio.
Αιτιολόγηση σχολίου / Εισήγησης
The National AI Research Fund is stated as a single line with an ambition: placing Cyprus among the top fifteen European nations for AI research excellence. However, there is no administering body, no allocation and no timeline. The AI ERC Bridge is a sub-bullet. Neither appears in the Annex F measurement framework. The Research and Innovation Foundation, which currently administers competitive national research funding, is named once in 101 pages, in the Legal Services annex, as a co-funder of compliance auditing rather than of research. Six research focus areas and a research excellence target cannot be delivered by instruments that have no owner, and the omission of the existing national funding agency from a national research strategy will be read either as an oversight or as a signal of institutional change. Either reading warrants clarification in the final text.
10. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 1.4.2 and 1.4.10 (printed pp. 4, 6); Section 3.2.1 (printed p. 20); Annex A, Digital, Cybersecurity and Data Frameworks (printed p. 54); Annex C, Healthcare (printed p. 68) and Maritime (printed p. 83).
Σχόλιο / Εισήγηση
Add the Data Governance Act, the Data Act, the Open Data Directive and the European Health Data Space Regulation to the instruments listed at §1.4.10, and convert the single bullet at §3.2.1 into a stated participation plan: which Common European Data Spaces Cyprus intends to join, in what order, which national body acts as counterpart in each, whether Cyprus will designate data intermediation and data altruism organisations under the DGA and which authority will register and supervise them, and how the national Trusted Maritime Data Space and the GHS health sandbox will connect to their European counterparts rather than operate as isolated national constructs.
Αιτιολόγηση σχολίου / Εισήγησης
The Strategy positions Cyprus as a trusted jurisdiction and a bridge between the EU and neighbouring regions, and Objective 6 commits to interoperable data foundations. Neither claim is supported by the current text, which refers to European data spaces only in general terms and to the EHDS only as a source of principles. The Data Governance Act, which is the legal instrument that makes cross-border data sharing operable and which imposes designation obligations on Member States, is not mentioned anywhere in the document. Sectoral data spaces built to national specification and later retrofitted to European ones cost substantially more than spaces built to the European reference architecture from the outset, and the Strategy elsewhere identifies avoidance of retrofitting as a design principle under “data by design.” Naming the instruments and the intended accession sequence is a drafting change with no cost that materially strengthens the interoperability commitment.
11. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 1.4.2, fifth bullet (printed p. 4); Section 1.4.6 (printed p. 5); Section 3.2.1 (printed p. 20); Section 3.2.2 (printed p. 20); Section 3.7 and 3.7.2 (printed pp. 38–39).
Σχόλιο / Εισήγηση
Separate the compute commitment from the data commitment. The fifth bullet of §1.4.2 should be limited to data infrastructure — secure processing environments, sectoral data spaces, and the API fabric — with compute capacity moved to §1.4.6, where it is already addressed. The Strategy should also resolve whether the national data architecture is federated (§3.2.1) or consolidated onto a shared platform (§1.4.2, §3.7.2), since these are incompatible.
Αιτιολόγηση σχολίου / Εισήγησης
Data and compute are governed by different legal regimes and require different institutional arrangements. Compute governance concerns capacity allocation, procurement and energy. Data governance concerns lawful basis, controllership, sectoral custodianship and the accountability of named data owners that §3.2.2 establishes. Describing them as one platform implies that whoever operates the national compute becomes the custodian of the national datasets placed on it, which would displace the data-owner model set out in §3.2.2 and create GDPR controllership questions for health, tax and justice data that the Strategy does not address. The conflation also produces a direct contradiction: §3.2.1 commits to a federated architecture that avoids unnecessary centralisation of sensitive information, while §1.4.2 commits to replacing scattered resources with a single shared platform. Both statements cannot be implemented.
12. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 1.5, success metrics (printed p. 6); Section 2.5.2 and 2.5.5 (printed pp. 16–17); Section 3.6.2 (printed p. 37); Annex C, Education and Human Capital Development — NASO and FutureAI CY (printed pp. 79–81); Annex F.
Σχόλιο / Εισήγηση
Add a tertiary capacity component to Objective 5 and to the Education pillar: a multi-annual programme of publicly funded additional undergraduate and postgraduate places in computer science, data science and artificial intelligence at the state universities, with the corresponding academic posts and laboratory capacity, and a funded doctoral scheme in the six research focus areas of Annex D. Enrolment and completion in these programmes should be a tracked indicator in Annex F, and NASO’s forecasting should feed directly into the allocation of places rather than only into reporting. The Strategy should also separate the labour-demand figure at §2.5.2 from the workforce-supply figure at §2.5.5, since they are currently the same number describing different things.
Αιτιολόγηση σχολίου / Εισήγησης
The Strategy sets a target of approximately 3,000 AI professionals by 2032 and then names no mechanism capable of producing one. CALF addresses ages 6 to 18 and produces no graduates within the Strategy’s horizon. FutureAI CY delivers micro-credentials of 5 to 15 ECTS to working adults, against 240 ECTS for a bachelor’s degree; these are valuable for AI literacy and workforce augmentation but do not produce AI engineers or data scientists, which the target explicitly names. NASO measures the gap and the talent-attraction measures at §3.6.5 compete for a scarce international supply, but neither adds domestic capacity. The absence of the state universities from the supply plan is a structural gap: they are the only institutions in Cyprus that can produce degree-qualified AI engineers, and expanding their capacity requires funded places and academic posts committed years ahead of the graduation date. A target set for 2032 with no undergraduate intake decision before 2027 cannot be met by domestic supply, which leaves attraction as the only remaining route. This instrument contradicts the sovereignty that is a goal.
13. Αρ. Άρθρου και εδαφίου στα οποία αναφέρεται το σχόλιο
Section 2.2.3, second paragraph (printed p. 10); Section 1.4.7 (printed p. 5); Section 2.5.3 (printed p. 16); Section 3.8 (printed pp. 40–42); Annex D, Focus Area 6 — Foundational AI Research (printed pp. 89–90).
Σχόλιο / Εισήγηση
Amend the second paragraph of §2.2.3 so that the observation about research translation is retained without implying that research which does not produce an operational solution has failed. Suggested reframing:” links between research and deployment remain uneven, and mechanisms for translating applicable research into operational solutions require strengthening, alongside sustained support for foundational research, which produces the methods, tools and trained researchers on which applied work depends and whose returns are realised over longer horizons.” Correspondingly, the prioritisation language at §1.4.7 and §2.5.3 should be balanced so that it does not subordinate the foundational research that Annex D Focus Area 6 identifies as a national priority, and the National AI Research Fund at §5 should carry a stated allocation for foundational work.
Αιτιολόγηση σχολίου / Εισήγησης
The observation that translation is uneven is fair and worth keeping. The framing, however, treats every research output that does not become an operational solution as a shortfall, which is not how research systems function: foundational work produces methods, evaluation techniques, tooling and trained researchers whose value is realised through later applied work, often by other groups and after long intervals. A national system that funds only research with an identified operational endpoint imports its foundations from elsewhere and forfeits the capacity to evaluate what it imports, which sits directly against Objective 8 on sovereign capability, since sovereignty in AI means the ability to understand and assess systems, not only to deploy them. The Strategy is also inconsistent on this point. Annex D names Foundational AI Research as one of six national focus areas, listing privacy-preserving learning, resource-efficient AI and robust anomaly detection, while §1.4.7 and §2.5.3 direct prioritisation toward applied and impact-oriented research. A focus area that is named as a priority in an annex and deprioritised in the funding language of the main text will not be funded. Doctoral training is the concrete case: it is the principal mechanism by which foundational research produces the skilled workforce the Strategy targets at §2.5.5, and it appears in neither the research nor the talent provisions.
CONTRIBUTION TO THE PUBLIC CONSULTATION ON THE DRAFT NATIONAL AI STRATEGY 2032 OF THE REPUBLIC OF CYPRUS
Submitted by Uncommon People Consulting, Sociedad Limitada (Spain), ESB16469710. http://www.uncommonpeople.eu. 27 August 2026.
COVER NOTE
1. We congratulate the National AI Taskforce and the Chief Scientist for Research, Innovation and Technology on a draft Strategy of unusual scope, and on its willingness to state the constraints as plainly as the ambitions. Four features are particularly welcome: the human-centred principle that runs through the document; the age-banded architecture of the Cyprus AI Literacy Framework; the teacher-mediated design of the Ethical Pedagogical Validation Layer; and, above all, the education pillar’s declared ambition, that Cyprus become a leading European hub for AI in education by 2032.
2. This contribution is authored by an independent strategic practice that has studied seventeen national AI-in-education programmes on three continents, and the Cypriot education landscape in depth. It is filed in the public interest. It seeks no contract for the delivery work it proposes, and no exception and no preference of any kind; Comment 12 states plainly what we would and would not accept, and on what terms.
3. This contribution concentrates on a single question: deliverability. We comment on the education pillar alone. Page 4 names a shortage of specialised AI skills among the Strategy’s structural weaknesses, and page 6 counts 3,000 or more AI professionals among its success metrics, beside modernised shipping, maritime, healthcare, tourism and professional services. The other pillars are where those people work; this is the pillar they come from. The education chapter itself warns that, without coordination, fragmented pilots will produce low impact and unequal access; every comment below is offered to strengthen the pillar’s path from framework to classroom. Twelve comments follow in the requested format, in four groups matching the four questions on which delivery depends. Who delivers: comments 1 to 3. What is taught, and how safely: comments 4 to 6. Where trust is built and systems are proven: comments 7 and 8. And how the work is measured, funded, and kept honest: comments 9 to 12.
4. Where this contribution points to a provision of the draft Strategy, it gives the section, page, or figure, so the reference can be checked in minutes. Statements about other countries rest on the accompanying annex, where each programme carries named, dated sources and estimates are identified as estimates. No factual claim in this contribution asks to be taken on trust. We have also read the whole record of this consultation as it stood on the day of filing, and where another contributor reached shared ground first, the relevant comment says so and seconds them: convergence among independent contributors is evidence in its own right, and the final text is easiest to strengthen where the record already agrees.
5. We wish to be plain about what we offer, and in what spirit. We have undertaken substantial preparatory work: benchmarking across seventeen national programmes on three continents; a study of the Cypriot education landscape in depth; and a complete, costed delivery design for a pillar of this shape, phased over five years, with governance, phase gates that can stop the work as well as advance it, a risk register, an evaluation framework, partner-selection criteria and the strategy for applying them, and a financial model reconciled to the Union instruments named in our tenth comment, showing how every component would be paid for. The philanthropic and private participation our eleventh comment contemplates is mapped within that model. We stand ready to present that work in full to the National AI Taskforce and the competent ministries, on request, without charge and without condition. And should the Taskforce or the ministries wish to discuss any part of it, we are at their disposal: a request suffices. We add one thing in candour: a contribution of this scope inevitably shows how we work, and we are content to be judged by it.
6. All of this work is offered in support of, and never in substitution for, the work of the National AI Taskforce and the competent ministries, whose frameworks the comments below take as their foundation.
7. One further conviction informs every comment below: implementation should build Cypriot capability rather than import around it. This consultation itself demonstrates the depth of the island’s ecosystem, with a ministry, statutory bodies, research figures, educators, technology firms, and AI vendors raising their hands in these very pages. Comment 12 turns that conviction into a mechanism the Republic can hold anyone to, including ourselves.
COMMENT 1: A NAMED DELIVERY VEHICLE FOR THE EDUCATION PILLAR
ARTICLE AND SECTION
Annex C, Education and Human Capital Development (pages 77 to 81); Section 3.5, priority sector 6.
COMMENT / SUGGESTION
The education pillar defines three excellent national instruments (CALF, EPVL, NASO) and a governance architecture for oversight, but names no organisation whose daily work is delivery: recruiting and training the teacher corps, producing and maintaining classroom materials, running pilots, and reporting results. We respectfully suggest that the final Strategy recognise a dedicated, independent, non-profit delivery vehicle for the education pillar, established as a foundation under Cyprus law, constituted on five principles: (a) government seats on its board alongside academia, the teaching profession, parents, and industry; (b) any private founders holding a structural minority, with an independent Cypriot chair; (c) statutory anchoring so the programme survives electoral cycles; (d) published audited annual accounts and independently evaluated results; and (e) recognition of the vehicle against published qualification criteria, so that any candidate, whatever its provenance, is measured to the same public standard.
JUSTIFICATION
The two national programmes most relevant to Cyprus by scale and ambition both run on precisely this model, and both appear in the literature the National AI Taskforce itself reviewed. Estonia’s AI Leap operates as a public-private partnership through a dedicated delivery organisation, with its pilot year supported by an investment of approximately EUR 4 million co-funded in equal parts by the Ministry of Education and Research and private partners; teachers were trained before students entered, and the programme launched nationally for upper-secondary grades in September 2025 with some 20,000 students and 3,000 teachers, expanding further in September 2026. Greece delivers national education programmes through the Onassis Foundation while the Ministry retains full ownership of policy and curriculum. The counter-examples are equally instructive: where national initiatives were run as procurement projects without a dedicated institution, notably the Republic of Korea’s AI Digital Textbook programme and the Los Angeles Unified School District’s device programme, they consumed public and private budgets measured in the hundreds of millions to billions of dollars and were reversed or abandoned within two years. The consistent lesson of these cases is that an institution, rather than a project, is what carries an eight-year target credibly. The pillar’s own stated goal, replacing fragmented pilots with a scaled, trusted national approach, is an organisational outcome and requires an organisation.
One further consideration strengthens the case: the draft establishes a considerable number of new institutional bodies, and none of them carries a stated budget or headcount. A delivery vehicle so recognised, arriving with funded capacity of its own, would be the exception that proves deliverability, an institution able to act from its first day.
One caution now on the record deserves adoption alongside the recommendation itself. A contributor writing as chair of a statutory national committee has observed that a strategy document can establish advisory, assurance and control-gate arrangements, but should not imply that any body holds licensing, enforcement or adjudicative powers the law has not conferred. We agree without reservation, and the recommendation is built for exactly that boundary: recognition in the Strategy does the work a strategy can do, naming the function and the published criteria, while powers, duties and permanence are conferred where alone they can be conferred, in law. The caution states, from institutional experience, exactly why point (c) asks for statutory anchoring: an eight-year programme needs both layers, and neither substitutes for the other.
A contribution to this consultation argues that the draft creates too many new bodies for an administration of this size, and sets a test for any that are created: demonstrate the capability gap, show why an existing institution cannot fill it, name the resources that will sustain it, and state how its contribution will be measured. We think that is the right test, and we would have this recommendation judged against it. The gap is the one this comment opens with. The reason an existing institution cannot fill it is the reason the international record gives: a ministry running this as a project, rather than an institution running it as its daily work, is what failed in Korea and in Los Angeles. The resources are private and philanthropic rather than a further call on the public payroll, so the vehicle adds delivery capacity without adding public administration, which is the concern the test exists to serve. The measurement is points (d) and (e) above. We would rather meet that test than argue with it.
Should the Taskforce find drafted wording useful, one sentence in the pillar’s implementation section would serve: ‘Delivery of this pillar will be supported by a dedicated, independent, non-profit delivery vehicle, with government and public-interest seats on its board, any private founders in a structural minority under an independent Cypriot chair, published audited accounts and independently evaluated results, recognised against published qualification criteria open to any candidate, and anchored in law.’
COMMENT 2: MAKING THE CERTIFIED-EDUCATORS COMMITMENT MEASURABLE
ARTICLE AND SECTION
Annex C, Education and Human Capital Development; Figure 10 (certified educators as an expected deliverable and KPI).
COMMENT / SUGGESTION
Figure 10 correctly lists certified educators among the pillar’s expected deliverables, and it is the only place in the pillar where that deliverable is named: the phrase appears nowhere in the chapter’s text. The chapter specifies no training volumes, no sequencing, and no certification body relationship beyond the committee structure. We recommend that the final Strategy commit to: (a) a numerical teacher-training target with dates, sized against the roughly 17,300 teachers serving at all levels of the Republic’s education system (17,298 in the Education Survey 2023/2024 of the Statistical Service of the Republic of Cyprus, the latest published); (b) an explicit sequencing rule that a first tranche of no fewer than 1,500 teachers is trained and certified before any classroom deployment of AI tools; (c) annual recertification so the corps keeps pace with the technology; and (d) that the deliverable be carried in the pillar’s text and not in a graphic alone, so that it survives the figure reconciliation proposed in our ninth comment.
JUSTIFICATION
Teacher readiness is the single strongest predictor of success or failure across national programmes. Estonia trained its teacher cohort before students entered the programme, and in its first year 94% of participating teachers used AI in their work, with 63% incorporating it into their teaching. The Republic of Korea deployed AI Digital Textbooks to classrooms in March 2025 ahead of teacher readiness; classroom adoption halved within a single term, from 37% to 19% of schools, and in August 2025 the National Assembly revoked the books’ textbook status, after a public commitment of roughly USD 850 million and private publisher investment reported at some KRW 800 billion, roughly USD 570 million, with teacher and parent unpreparedness cited among the leading causes. Finland’s Elements of AI and the United Kingdom’s National Centre for Computing Education both demonstrate that a certified educator pipeline is buildable at national scale within one to two school years when it is planned first. A deliverable that appears only in an infographic is also a deliverable that escapes text search, and therefore the one most likely to be lost in an editorial pass or overlooked by the ministries implementing the pillar; writing it into the chapter costs a sentence and secures the commitment. Attaching a numerical target here is precisely the kind of strengthening this consultation invites. The record of this consultation now carries an educator’s proposal for a national teacher training and certification programme built around a levelled Cyprus AI Educator Certificate, kept current as the technology moves, and, from a second contributor, a call for a structured national professional development programme for teachers and academic staff carrying measurable participation and competency targets. We second both with enthusiasm, and they complete one another: the certificate gives the commitment its instrument, the competency targets give it a standard, and the volumes and dates above give both their scale, their sequence and their cadence. Adopted together, they would leave Figure 10’s certified-educators deliverable with a name, a standard, a volume, an order and a renewal cycle: everything a deliverable needs in order to be delivered.
COMMENT 3: PILOT BEFORE SCALE, WITH PUBLISHED GATES
ARTICLE AND SECTION
Annex C, Education and Human Capital Development (implementation); Annex B, AI Use Case Lifecycle and Control Gates.
COMMENT / SUGGESTION
The draft’s Annex B establishes a disciplined lifecycle with control gates for AI use cases across government. We suggest the education pillar apply that same discipline to itself, explicitly: (a) a named pilot phase of 25 to 30 schools selected by published criteria across urban, rural, and disadvantaged catchments; (b) a published review at the end of the pilot year, with pass criteria defined in advance; and (c) explicit authority at each gate to stop, extend, or redesign before national scale-up. The pilot’s evaluation should be independent and its results published regardless of outcome.
JUSTIFICATION
The most expensive education-technology failures of the last decade share one feature: scale preceded evidence. The Los Angeles Unified School District committed approximately USD 1.3 billion to a district-wide device deployment before its curriculum was complete; the programme collapsed within two years and ended in litigation. The Republic of Korea scaled nationally in a single step, with the outcome described in the previous comment. By contrast, the United Arab Emirates piloted, embedded, and then scaled, and its programme endures; Estonia began with two grade cohorts and published its adoption data, favourable and unfavourable alike. Cyprus’s size is a strategic advantage here: a 25 to 30 school pilot is a meaningful sample of the entire system, something no large country can say, and the draft Strategy elsewhere recognises exactly this rapid-validation advantage in its research annex. The failure mode has a name in the Strategy itself. Page 4 lists among its structural weaknesses a risk of “AI theatre”, many experiments and little impact, and page 63 answers that warning for the Government pillar with an explicit discipline of outcome-led selection focused on measurable results. The education pillar is given no equivalent, and published gates are how that discipline reaches the classroom. Publishing the gates in advance also protects the Strategy itself: pausing a pilot against published criteria reads as prudence, while pausing a national rollout is a far harder story for any government to tell. The record of this consultation asks for the same discipline from several directions, entry and exit criteria for pilots and clearer tests for the passage from pilot to production among them; what this comment adds is the education pillar’s own version: the named pilot, the published criteria, the independent evaluation, and the authority to stop.
COMMENT 4: EMBED AI LITERACY RATHER THAN ADD IT, AND PILOT THE CALF RUBRICS WITH TEACHERS
ARTICLE AND SECTION
Section 3.6.1 (AI literacy and awareness); Annex C (Cyprus AI Literacy Framework).
COMMENT / SUGGESTION
We warmly endorse CALF’s four developmental bands and their alignment with the Key Competences for Lifelong Learning and the UNESCO and OECD competency frameworks. Three suggestions to strengthen implementation: (a) pilot the classroom-ready assessment rubrics jointly with the first teacher-training wave, so the instrument and its users are validated together rather than sequentially; (b) state explicitly that CALF outcomes are delivered by embedding within existing subjects (mathematics, science, languages, design and technology) rather than through new standalone timetable hours; and (c) specify accessible-by-design outcomes in the rubrics, so that learners who use assistive technology are inside the framework rather than exempted from it.
JUSTIFICATION
Joint piloting halves the calendar and surfaces the real failure modes: a rubric that works in a specification but not in a classroom is discovered only when trained teachers use it with real students. On embedding: the United Arab Emirates reached national coverage in months by placing AI content inside existing subjects, where there was nothing to displace and therefore nothing to negotiate. Reforms built on new timetable hours face the opposite arithmetic: an hour must be taken from something, and whatever it is taken from has a constituency. The Strategy states the embedding principle in mandatory terms twice, on consecutive pages. Page 25: “AI initiatives shall be embedded within existing policy, operational and accountability structures and shall not be treated as standalone or experimental activities.” Page 26 repeats it in slightly different words. Both provisions address how ministries adopt AI rather than how a curriculum is built, but the logic is identical, and the education pillar does not apply it. Embedding also reaches every learner rather than only those who elect a new subject, which serves the pillar’s own inclusion commitments. One further point belongs with the rubrics. On page 77 the pillar states that all learners, including vulnerable groups, should benefit from inclusive, accessible design, and on page 79 it gives the Pedagogical and AI Safety Committee, the body that maintains the CALF rubrics, the further task of validating accessibility checks. CALF’s outcomes, however, are banded by age alone, so that committee is asked to validate accessibility against a framework which does not express it. Specifying accessible-by-design outcomes within the existing bands would give the commitment its instrument, and would place the learners who use assistive technology, whether captioning, text-to-speech, reading support or communication aids, inside the framework rather than beside it.
COMMENT 5: EPVL: SPECIFY THE SAFETY INSTRUMENT BEFORE ANY CLASSROOM DEPLOYMENT
ARTICLE AND SECTION
Annex C, Education and Human Capital Development (EPVL, including the provision that it “will be specified in a separate technical and pedagogical annex”).
COMMENT / SUGGESTION
The Ethical Pedagogical Validation Layer is, in our reading, the pillar’s most important safety commitment: teacher-mediated, age-aware, culturally respectful, and auditable. Because the draft defers its specification to a future annex, we would ask the final Strategy to add four commitments, three of sequence and one of content: (a) the EPVL technical and pedagogical annex is published for consultation before any classroom deployment of AI tools; (b) EPVL validation is operational for a tool before that tool reaches students, without exception; (c) EPVL is piloted alongside the first teacher-training wave so its audit and mediation workflows are shaped by practising teachers; and (d) the annex names child-specific protections explicitly: exclusion of engagement-maximising, addictive, manipulative and deceptive design patterns, prohibition of commercial profiling of minors’ data, age-appropriate design standards for every interface a student touches, and confirmation that no deployed system infers emotions from biometric data, which Union law already prohibits in education institutions.
JUSTIFICATION
Deploying classroom AI before its validation layer exists would invert the pillar’s own logic and create avoidable exposure under Union law: AI systems in education fall within the high-risk regime of the Artificial Intelligence Act, whose education obligations apply from 2 December 2027 following Regulation (EU) 2026/1744. An operational EPVL is very close to a ready-made conformity and human-oversight architecture for that regime; sequenced correctly, Cyprus would arrive at the compliance deadline with an instrument other member states will still be designing. Sequenced incorrectly, the Republic would be retrofitting safety onto systems already in front of children, which is the costliest order of operations in both money and trust. The fourth ask closes a gap that runs wider than this pillar. The draft’s only provision touching minors is EPVL’s check on age appropriateness, which asks whether material suits a child, not whether a system is built to exploit one; addictive design, the commercial profiling of minors’ data, and age-appropriate design standards appear nowhere in the document, though children are the Strategy’s youngest and least defended users. The EPVL annex is the natural home for those protections, and a single annex can close the gap for the entire document. The record of this consultation shows other contributors pressing the same protections, and we second them gladly; what this comment adds is the sequence and the home: the protections named inside the EPVL annex, and the annex operational before any tool reaches a student. Should the Taskforce wish to draft the protections now, one paragraph would serve, the last of its four requirements restating a prohibition already in force rather than proposing a new one: ‘Every AI system deployed in classrooms shall exclude engagement-maximising, addictive, manipulative and deceptive design patterns; shall not profile minors for commercial purposes nor permit reuse of their data for such profiling; shall conform to age-appropriate design standards for every interface a student touches; and shall not infer emotions from biometric data, which Article 5 of the Artificial Intelligence Act already prohibits in education institutions. EPVL validation verifies each requirement, per tool, before deployment; its findings are auditable; and a teacher, parent or student has a named route to report a suspected breach after deployment.’
COMMENT 6: PAIR AI LITERACY WITH ROBOTICS: THE MIND AND THE BODY OF THE MACHINE
ARTICLE AND SECTION
Annex C, Education and Human Capital Development; Annex D, Focus Area 2 (Autonomous Systems); Section 3.8.5 (National Testbeds); Section 5 (Autonomous Systems Park).
COMMENT / SUGGESTION
Robotics is present in the draft’s research agenda (Annex D names robotic perception, human-robot interaction, and swarm systems) and in its innovation infrastructure (the planned Autonomous Systems Park), yet it is absent from the education chapter. We suggest that the final Strategy: (a) pair AI literacy with robotics and physical computing as one curriculum strand, built on programmable microcontroller hardware of the micro:bit or Arduino class, at tens of euros per learner rather than thousands per room, so that learners meet both the reasoning of the machine and its physical expression, and so that the strand reaches every school on operating budgets without waiting on a capital programme; (b) connect the education pillar explicitly to the Autonomous Systems Park, giving schools a national venue for applied robotics, and provide that, where learners are present, the “clearly defined operational, legal, safety, and ethical boundaries” the draft already promises for its testbeds gain a pedagogical limb: teacher-mediated access and human-in-the-loop supervision of the kind EPVL establishes for classroom AI, extended to physical systems, since the safety case for a child beside an autonomous vehicle is not the safety case for a child at a screen; and (c) establish a national student robotics competition structure, with regional leagues feeding an annual final.
JUSTIFICATION
The case is practical before it is cultural, and inexpensive before it is either. Physical computing is not an enrichment of AI literacy but its completion: a learner who has only ever seen a model’s answer on a screen has not met the point at which code acquires consequences, and that is precisely the point at which autonomous systems are engineered. Screen-based literacy alone also loses the learners who learn by building, among them many of the engineers a national strategy most needs, and a programmable board costing tens of euros gives exactly those learners their way in. The deployment arithmetic follows: a strand built on hardware at that price is a recurring operating line rather than a capital programme, so it can begin in the pilot schools and reach the network without waiting for buildings. The engagement evidence is international and durable, with competition circuits such as FIRST and the World Robot Olympiad sustaining participation at national scale across income levels. The draft itself supplies the remaining pieces of the argument. Annex D observes that Cyprus’s scale supports rapid validation cycles and practical pilots, and names human-robot interaction “to ensure safe, trusted collaboration” among its research priorities: the education pillar is where that research meets its youngest subjects. The Autonomous Systems Park is a capital investment in drones, autonomous vehicles and robotics whose return depends on people who can build, operate and maintain them, and a park without a domestic pipeline staffs itself by import. That pipeline can only begin in schools and runs on a decade’s lead time: the cohort that meets its first microcontroller in gymnasio is the cohort that staffs the Park in the 2030s. A generation that has built and programmed machines by the age of eighteen is the surest route to the Strategy’s own target of 3,000 or more AI professionals, and the cheapest. And there is a cultural claim waiting to be made: the first imagined humanoid machine in world literature, Talos, guarded the shores of Crete, an island of the same sea. Pairing the mind and the body of the machine in Cypriot classrooms is not an import but a homecoming.
COMMENT 7: A PUBLIC VENUE WHERE THE STRATEGY MEETS ITS PUBLIC
ARTICLE AND SECTION
Annex C, Education and Human Capital Development (national ambition and trust); Section 3.5 (public-private collaboration principle).
COMMENT / SUGGESTION
We propose the addition of a public engagement dimension to the education pillar: a flagship public venue for AI and robotics learning, open to families and visitors as well as schools. Without specifying any site, scale, or design, the venue’s uses can be named now, because each answers a commitment the pillar has already made: for schools, curriculum-linked visit programmes that extend the classroom rather than interrupt it; for teachers, a permanent home for certification days, training cohorts, and the shared practice a dispersed profession otherwise never develops; for families, exhibitions and community days where parents watch their children programme a moving machine; for adults, short reskilling courses run with the training institutions the Republic already funds; for students, a national stage for the robotics leagues proposed in our sixth comment; and for the Republic, a place where the Strategy can be seen: the venue that hosts the delegations, the student finals, and the annual summit its international ambitions deserve. Curriculum reform is, by its nature, invisible to the public that funds it; a place with those uses converts an administrative programme into a national story, and public trust, which the pillar itself identifies as a condition of success, is built far faster in person than on paper.
JUSTIFICATION
The European science-centre evidence is long-standing and quantified. Estonia’s AHHAA centre in Tartu attracts in the order of a quarter of a million visitors a year (246,434 in 2023, as published by the centre) in a city of roughly 97,000 inhabitants, and centres of its class typically recover a substantial share of operating costs through admissions, programmes, and events, limiting the long-term call on public operating budgets. The capital is a separate question with a separate answer: a venue of this kind is the sort of investment Union cohesion instruments exist to co-finance, alongside the co-funded partnerships the pillar’s own public-private collaboration principle already contemplates.
The obvious follow-up deserves a direct answer too: why not use what exists. The island’s universities and research centres are designed for researchers and enrolled students, and their opening hours, safety regimes and layouts follow from that purpose; none is built for a class of thirty on a Tuesday morning or a family on a Saturday afternoon. A public venue is a different instrument, and the two are complements rather than alternatives: the venue draws its content, its demonstrations and much of its expertise from those institutions, and gives them a public face they were never built to provide.
A venue of this kind also carries a value the pillar’s text does not yet name: international visibility. A national centre hosting ministerial delegations, international student competitions, and an annual regional summit places the Republic’s education initiative in front of the world’s press and policy community on a recurring calendar, coverage of a kind small states rarely obtain and never at this cost. It also gives the pillar’s other instruments a home: teacher certification days, CALF assessment pilots, student competitions, and public demonstrations of exactly the human-centred AI the Strategy promises. Neutral ground may be its quietest value: the one floor where more than one provider’s systems can stand side by side, under the same roof and the same rules, compared in public rather than chosen in private. Several contributions to this consultation warn against dependence on any single provider; a place built for plurality is that warning heeded in architecture, and it changes the Republic’s position in every negotiation that follows, because a state that can compare is a customer every provider must court. Nor need that plurality be left to hope: the timing favours the Republic for reasons set out later in this contribution, and the preparatory work behind it addresses how such participation would be assembled and on what safeguards; the detail travels with the rest of our work, on request.
No square metre or site need be specified in the Strategy; recognising the venue dimension as part of the pillar is sufficient to enable it. If the Taskforce wishes to make that recognition operative, one sentence would do so: tasking the pillar’s implementation phase with a feasibility assessment of such a venue, drawing on the European science-centre model, converts recognition into a datable, ownable action while committing the Republic to nothing beyond the study itself.
COMMENT 8: SCOPE A NATIONAL REGULATORY SANDBOX TO EDUCATION
ARTICLE AND SECTION
Section 3, subsection headed “Enabling Responsible Experimentation”; Section 5, Immediate Steps (industry sandboxes programme); Annex B.
COMMENT / SUGGESTION
We would encourage the Taskforce to name education explicitly as a domain of the planned national sandbox architecture. Under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, every member state must have at least one national AI regulatory sandbox operational by 2 August 2027, and the same instrument applies the high-risk regime to education systems from 2 December 2027. Scoping a sandbox to education converts a compliance obligation into the pillar’s own testing infrastructure: classroom AI tools, the EPVL validation layer, and teacher-facing systems could each be validated under supervision before deployment.
JUSTIFICATION
Education combines the Strategy’s most sensitive user population, children, with its hardest Union-law deadline, which argues for the most structured testing environment the state can offer. A named education sandbox would also be an early-mover position in the Union: few member states have scoped their sandbox obligations by sector, and the first to run classroom AI through a supervised sandbox would be well placed to shape the practice others follow. The draft’s Annex B control-gate lifecycle supplies a ready-made evaluation framework; the sandbox gives those gates a home.
COMMENT 9: RECONCILING THE STRATEGY’S TARGETS, DATES AND FIGURES BEFORE ADOPTION
ARTICLE AND SECTION
Annex C pages 77 to 81 (education pillar, including Figure 10); Figures 5, 7 and 11 (pages 64, 71 and 85); Section 3.5, Healthcare (pages 33 to 34) with Annex C page 68; Section 1.5; Section 2.2.1.
COMMENT / SUGGESTION
In the spirit of strengthening the final text, we note the following for the editorial pass. These notes begin in the education pillar and end in a pattern that affects the document as a whole.
(a) The education pillar’s 2032 adoption target reads 75% in the priority-sector summary and in the pillar table on page 81, but 50% in the Figure 10 infographic printed immediately beneath that table on the same page; the final text may wish to reconcile the two. A related reconciliation would strengthen the whole document: 75% appears as a target in three different scopes, industry adoption by 2030 (Section 5, Immediate Steps, under “Accelerating Adoption and Industry Readiness”, page 51), overall adoption by 2032 in the Government pillar (cited as in line with the Digital Decade target, whose own form is 75% of enterprises by 2030), and education and labour by 2032 in Annex C. Stating each pillar’s target once, with its own scope and date, would remove any doubt about what is promised, to whom, by when.
(b) The pillar’s baseline, 13% adoption across education and labour, carries no stated source and no metric definition: it is not specified as a share of teachers, students, schools, workers, or enterprises. The document itself shows the form the figure needs: the enterprise-adoption baseline of 9.27% in Section 2.2.1 is defined, given a trend (an annual progression of 17.3% since 2024) and set against a comparator (the EU average of 19.95%), and giving the 13% the same three-part treatment would let the pillar’s headline target be measured with the same confidence. The subsection headed “Strategic objectives and 2032 target” would also benefit from stating the target as a number.
(c) Page 79 twice renders the Deputy Ministry’s name as the Deputy Ministry of Digital Policy, Research and Innovation; the official form, used elsewhere in the Strategy including on page 80 of the same annex, is the Deputy Ministry of Research, Innovation and Digital Policy.
(d) The Figure 10 variance does not appear to be isolated. Because the pillar infographics are images, their content escapes text-based checking, and reading them figure by figure against the surrounding text shows the same pattern in three further pillars: Figure 5 (Government, page 64) gives 75% adoption “by 2030”, the 40% reduction in citizen waiting times “by 2030”, and intelligent governance “by 2035”, where the pillar text gives 2032 for all three; Figure 7 (Healthcare, page 71) gives virtual human twins “by 2035”, agreeing with the pillar’s deliverables table on page 70, while the pillar’s text on page 68 gives 2032 for the same deliverable; and Figure 11 (Shipping, page 85) gives the Intelligent Maritime Orchestrator ambition and its capability KPI “by 2035”, where the pillar text gives 2032. We would respectfully suggest a figure-by-figure reconciliation pass before adoption, so that the final Strategy states each of its targets once, identically, in text and graphic alike.
(e) The same reconciliation is needed where the body text dates its own deliverables. On page 33, the Secure National Health Data Repository initiative states that its governance arrangements “will be elaborated in the dedicated AI healthcare strategy, to be developed by December 2027”; on page 34, the same chapter closes by stating that “a full-scale AI healthcare strategy is recommended for development by 2028”; and the Annex C healthcare pillar repeats the 2028 form on page 68. As drafted, the same instrument appears to carry two dates and two statuses, a commitment on one page and a recommendation on the next; and because a named initiative expressly defers its governance detail to that strategy, the strategy’s date and status deserve to be stated once. If two distinct documents are intended, saying so expressly would serve the same end.
(f) In Section 1.5, the three relative implementation windows (0 to 8, 6 to 12, and 12 to 24 months) carry no stated start date, and two of the seven success metrics are prefaced “Recommended”; anchoring the windows to a date and firming the verbs would strengthen the scorecard against which the Strategy will be measured.
(g) The certified-educators deliverable would benefit from the numerical targets suggested in our second comment.
JUSTIFICATION
These notes are offered with genuine appreciation for the scale of drafting the Taskforce has undertaken; documents of this breadth inevitably accumulate small variances, and this one carries remarkably few in its text. Other contributors have noticed some of the same variances: one asks that the final text distinguish committed targets from strategic ambitions and scenario estimates, which is the point made at (f) above approached from another direction, and another asks that every indicator carry a definition, baseline, data source and named owner, which is the general form of the point made at (b) above; all three strengthen the case for one reconciliation pass before adoption rather than corrections piecemeal. The graphics deserve particular attention for exactly that reason: because figure text cannot be searched, variances there are the likeliest to survive into the adopted Strategy, and those noted above were found only by reading every pillar figure against its surrounding text. The stakes are practical rather than editorial: points (d) and (e) in particular bear on measurement rather than wording, and may merit the attention of those who own the targets as well as of the editorial pass. Foundational numbers and dates are inherited downstream by procurement documents, KPI dashboards, and ministry work plans, and no pillar can be delivered against a target the document states two different ways. All of this is easiest to align while the text is still open.
COMMENT 10: A FUNDING ARCHITECTURE FOR THE EDUCATION PILLAR
ARTICLE AND SECTION
Section 3.10 (sustainability and economic model); Section 1.4.9; Annex C (Education and Human Capital Development).
COMMENT / SUGGESTION
We recommend that the final Strategy attach a funding architecture to the education pillar: at minimum, a mapping of the Union instruments available to it, and ideally an indicative envelope. The instruments are substantial and already aligned with the pillar’s components: Erasmus+ Teacher Academies for the certified-educator pipeline; Digital Europe Programme skills actions for advanced digital capability; Horizon Europe, including the Teaming instrument that Cyprus has used successfully before, for the research dimension; and the Thalia 2021-2027 cohesion programme for physical infrastructure.
JUSTIFICATION
Every expected deliverable of the education pillar depends on sustained funding, yet the pillar carries no financial reference of any kind, a silence it shares with the Government, Healthcare, and Tourism pillars, in a document whose only programme-level financial figures are the EUR 5,000 threshold of the AI Judge capability and the EUR 1 million per round of the investment-matching fund. The education pillar is where that silence costs most, because its deliverables are recurring rather than one-off: teachers must be trained and recertified every year, content maintained, and evaluations published for as long as the pillar lives. The benchmark evidence should encourage rather than daunt: Estonia runs its pilot year on approximately EUR 4 million, co-funded in equal parts by the state and private partners, achieved by sequencing teachers first and adapting existing tools rather than commissioning new platforms. Naming the available instruments costs the Republic nothing, signals seriousness to the Union bodies that co-fund such work, and answers in advance the first question every implementing ministry will ask: who pays. Other contributions to this consultation have remarked on the same silence; this comment differs in offering the remedy, the instruments named and the mapping made.
COMMENT 11: WELCOMING CO-FUNDED DELIVERY PARTNERSHIPS
ARTICLE AND SECTION
Annex C (Education and Human Capital Development); Section 3.5 (public-private collaboration principle).
COMMENT / SUGGESTION
Finally, we invite the Taskforce to consider one enabling sentence in the education pillar: ‘The Republic welcomes co-funded delivery partnerships, including philanthropic participation, for the implementation of this pillar, under public governance safeguards and the compliance framework this Strategy establishes.’ Should the Taskforce wish to make that welcome operative, a second sentence would do so: ‘The implementation phase will convene prospective co-funders, philanthropic and corporate, under the same safeguards.’ Together they give interest a named public doorway and the Republic the convening seat.
JUSTIFICATION
The draft already embraces public-private collaboration as an adoption principle; this suggestion simply extends that principle explicitly to the education pillar, where the international precedents are strongest. Estonia’s programme is co-funded in equal parts by the state and private partners through a dedicated delivery organisation; Greece’s most significant national education programmes are delivered with philanthropic institutions under ministry policy control. Demand for such partnerships will not need to be manufactured: the Union’s classroom-AI obligations take effect on 2 December 2027, and providers will need demonstrably compliant national deployments inside an EU jurisdiction before that date. An explicit welcome in the final text gives any future partner, and the Republic itself, a clear and orderly doorway, with the state holding the keys; and a pillar that admits more than one partner under identical terms and independent evaluation keeps the Republic permanently in the stronger position. One further observation belongs here, because the record of this consultation will be read by more than its addressees. The architecture the draft already contains, public governance, independent evaluation, control gates that can stop work, and published results, is precisely the architecture serious philanthropy requires before it commits; the draft has, perhaps without intending it, already written the assurance side of a co-funding agreement. What is missing is only the invitation. Foundations do not volunteer into silence. An explicit welcome in the adopted text is how both kinds of participation become proposable in Cyprus: the mission philanthropy that funds national education delivery in Greece, and the private co-funding that carries half of Estonia’s. We would discuss either kind with the Republic gladly, whenever asked.
COMMENT 12: OPEN PROCUREMENT FOR THE PILLAR’S RECURRING DELIVERY WORK, AND A DECLARATION OF INTEREST
ARTICLE AND SECTION
Section 3.3.2, Control Framework (approval gates before procurement; approved and certified delivery and implementation partners); Annex C, Education and Human Capital Development; Annex F (national KPIs and measurement framework).
COMMENT / SUGGESTION
We recommend that the final Strategy commit the education pillar’s recurring delivery work, systems integration, content production, training logistics, and platform operations, to open, competitive procurement, and that Annex F carry an indicator reporting annually the share of that contract value awarded to Cyprus-resident suppliers. A declaration of interest belongs beside that recommendation, so that it binds its proposer first. We are an independent practice, not a candidate delivery vehicle, and we hold no interest in any body that is, as at the date of this contribution; should that change, we would say so. We have prepared, at our own cost, a complete implementation plan of the kind these comments describe, and we would wish to see such a programme built, by whichever body the Republic’s published criteria select. That plan is offered to the Republic without charge and without condition. We seek no exception and no preference: if we were ever engaged in connection with this pillar, whether by the Republic or by a body funding the work, that engagement would come either through open competition or on ordinary commercial terms openly stated, on the same footing as any other candidate. The division of labour we advocate binds us first: the recurring delivery work this comment commits to open procurement, the systems, the content, the logistics and the operations, belongs to the market, Cypriot firms foremost, and we would take no part in it; designing how an institution is to work and operating it are different trades, and we do only the first, save for one bridge between them which the list below names and bounds. Our own part in this pillar is strategy, and if the Republic or a funder ever sought that work from us it would be strategic work of the kinds this contribution has already required: assembling and sequencing the applications to the Union instruments named in our tenth comment, with the case-building each one needs; keeping the design current as Ministry data arrives, as Union law moves and as the international evidence changes; transitional programme coordination until the delivery body’s own leadership is in post, which is that bridge: work someone must do before the institution exists to do it itself, ending on an appointment we do not make; the design of that body’s operating model and of the performance framework it reports against; and supporting the Republic in convening the international participation described above, the Republic holding the convening seat throughout. None of that is delivery work and none of it is the delivery role itself, and any of it would be commercially negotiated on the terms just stated. We would not evaluate what we designed: the independent evaluation our third comment asks for must be independent of us too. We state this plainly rather than leave it to be discovered.
JUSTIFICATION
The draft returns to small and medium-sized enterprises throughout, more than twenty times across its chapters, and the commitment is unmistakable. What the text does not yet carry is the machinery that would deliver it: lot design, reserved participation, and an indicator tracking the share of contract value that remains with Cyprus-resident firms. The education pillar is a natural place to begin, because its delivery work recurs by nature, and spend that is procured openly circulates through the island’s own technology sector year after year, strengthening the ecosystem the Strategy sets out to grow. We note with agreement that other contributions to this consultation have proposed kindred machinery: reserved procurement lanes for Cyprus-resident SMEs, with express indicators for the AI contract value awarded to them. The placement is this comment’s addition: an indicator carried in Annex F, which the record elsewhere also asks to hold outcome indicators of other kinds. One such contributor, a Cypriot vendor, stated its own interest as plainly as we state ours; we simply stand on the other side of the same disclosure, a Spanish practice proposing an indicator that counts a category which cannot include us. A mechanism urged both by those it would include and by those it cannot include arrives corroborated on the only ground that matters. The declaration above is offered in the same spirit: we would rather be held to it than believed. A practice that asks for open procurement, states its own interest plainly, and accepts for itself the criteria it proposes for others, gives the Republic something it can check.
ANNEX: WHAT SEVENTEEN NATIONAL PROGRAMMES TEACH
This annex summarises publicly documented outcomes of national AI-in-education and related digital-education programmes reviewed for this contribution: Croatia, Estonia, Finland, France, Greece, Malta, the United Kingdom, the United Arab Emirates, Qatar, Saudi Arabia, Israel, Singapore, South Korea, Japan, China, India, and the United States. All figures are as publicly reported at the date of filing; sources are named for each programme, and where a figure is an estimate the text says so.
A. DELIVERY MODELS THAT WORKED, AND WHY THEY WORKED
Estonia. The AI Leap programme launched nationally on 1 September 2025 for upper-secondary grades, with some 20,000 students and 3,000 teachers, and expands in September 2026 to vocational schools and new cohorts, adding roughly 38,000 further students. It operates as a public-private partnership through a dedicated delivery organisation; the pilot year is supported by approximately EUR 4 million co-funded equally by the Ministry of Education and Research and private partners including Telia, Skaala, and the Smart Future Fund. Teachers were trained first, and the effect shows in the first-year results: 94% of participating teachers used AI in their work and 63% incorporated it into their teaching. Estonia also publishes its adoption data candidly, including the less flattering weekly-use figures, and adjusts accordingly; that habit of published honesty is itself part of the model. A country of comparable size to Cyprus, spending in the low single millions, is now the reference point for an entire continent. Sources: Ministry of Education and Research announcement of the AI Leap programme (hm.ee, February 2025); TI-Hüpe programme site and first-year results (tihupe.ee, 2026), which also name the co-funding partners.
Greece. National-scale education delivery in partnership with the Onassis Foundation, with the Ministry retaining full ownership of policy and curriculum; separately, a national agreement bringing AI tools into schools. The significance of the model is what it removes: no procurement friction, no political ownership battles, and delivery capacity that does not depend on the electoral cycle, all while the state keeps every decision that belongs to the state. Sources: Ministry of Education of Greece; Onassis Foundation.
United Arab Emirates. AI content embedded within existing subjects, enabling nationwide coverage within months rather than years, scaled after piloting, and still operating and deepening today across all school grades. The demonstration that speed and durability are compatible when the sequencing is right. Sources: UAE Ministry of Education announcements.
Finland. Elements of AI, a university-led open course, made AI literacy a mass phenomenon, reaching, as publicly reported, more than a million learners across dozens of countries from a standing start, and proving that well-designed content, not expensive platforms, is the scarce ingredient. Sources: University of Helsinki and MinnaLearn, Elements of AI enrolment reporting (elementsofai.com).
United Kingdom. The National Centre for Computing Education built a national teacher-certification pipeline for computing through a network of hubs and subject-knowledge certificates, upskilling teachers by the tens of thousands: the closest operational template in Europe for a certified-educators KPI with real numbers attached. Sources: National Centre for Computing Education impact reporting (teachcomputing.org); Department for Education.
Singapore. Sustained, incremental integration of AI into schooling under successive national masterplans, with teacher capability treated openly as the binding constraint and adaptive learning systems introduced only as that capability matured. Sources: Ministry of Education of Singapore.
B. CAUTIONARY EVIDENCE: HOW NATIONAL PROGRAMMES FAIL
South Korea. The chronology deserves attention because it is recent and complete. The AI Digital Textbook plan was announced in June 2023; 76 textbook titles were approved in September 2024; the books entered classrooms with the school year in March 2025, ahead of teacher readiness and without a gated pilot. Classroom adoption fell from 37% of schools in the first semester to 19% in the second, and in early August 2025 the National Assembly amended the law to strip the books of textbook status, reclassifying them as supplementary materials and ending their funding mandate. The public commitment is reported at roughly USD 850 million, participating publishers invested a reported KRW 800 billion, roughly USD 570 million, and the 2026 digital-education budget was subsequently cut to roughly one sixth of its prior level. One of the most digitally advanced school systems on earth, with resources few nations can match, lost its programme not to technology but to sequence. Sources: Korea Herald, “South Korea pulls plug on AI textbooks” (August 2025); Rest of World, “South Korea’s AI textbooks fail after rushed rollout” (2025); Ministry of Education of Korea announcements and National Assembly proceedings, 2023 to 2025.
United States (Los Angeles). A district-wide device programme of approximately USD 1.3 billion, launched in 2013 before its curriculum was complete, collapsed within two years amid procurement failures and a December 2014 federal investigation, and Pearson settled with the district for USD 6.45 million in October 2015. A single school district outspent most national education budgets, and its experience is now part of the evidence every later programme can draw on. Sources: contemporaneous United States reporting, 2013 to 2015; the federal investigation of December 2014 and the Pearson settlement of October 2015 are matters of public record.
China and Japan. Large-scale national pushes illustrate both the productivity potential of AI in learning analytics and the governance questions raised by classroom surveillance applications; the human-centred boundary the draft Strategy sets is the correct one, and worth defending explicitly as deployments scale. Sources: national policy documents; OECD reviews.
The warning these cases carry is specific, not general. Korea’s reversal is barely a year old. Both failures occurred in systems with far greater resources than any small state commands, and in both cases the missing elements were exactly those the draft’s education pillar currently leaves unspecified: teacher volumes, pilot gates, a delivery institution, and a funding architecture. The comments in this contribution ask for nothing more than the insertion of those elements while the text is still open, because every one of them has already been paid for, expensively, by someone else.
C. INVESTMENT CONTEXT
Israel, Qatar, Saudi Arabia, France, India, Malta. Each is investing systematically in AI skills through national strategies, dedicated institutes, or school programmes, confirming that the education-AI race is global and that windows of distinction close quickly. Croatia’s BrAIn programme, listed above and reviewed on the same basis, run by the CARNET network under the Ministry of Science, Education and Youth with EUR 16 million of funding, 85% of it from the European Social Fund Plus, brings AI curricula into schools as elective and extracurricular subjects from the 2025/2026 school year: the nearest EU signal that first-mover room inside the Union is finite. Sources: CARNET BrAIn project documentation (carnet.hr); national AI strategies; EU monitoring.
D. THE PATTERN, IN ONE PARAGRAPH
Across seventeen programmes the pattern is stable: initiatives succeed when teachers precede students, pilots precede scale, content precedes hardware, delivery has an institution rather than a project office, and evaluation is independent and published. They fail, at costs measured in the hundreds of millions to billions, when any of those orders is reversed. Cyprus’s draft Strategy already contains the principles; the comments above ask only that the final text bind them to the education pillar with numbers, sequence, and a named delivery function, qualified against published criteria.
Σχόλια Διεύθυνσης Νοσηλευτικών Υπηρεσιών Υπουργείου Υγείας
Η Διεύθυνση Νοσηλευτικών Υπηρεσιών του Υπουργείου Υγείας αναγνωρίζει ότι η Τεχνητή Νοημοσύνη (ΤΝ) αναμένεται να διαδραματίσει καθοριστικό ρόλο και στον ψηφιακό μετασχηματισμό του Συστήματος Υγείας, συμβάλλοντας στη βελτίωση της ποιότητας των παρεχόμενων υπηρεσιών. Ως εκ τούτου είναι σημαντικό στην Εθνική Στρατηγική Τεχνητής Νοημοσύνης να συμπεριληφθούν ή και να αναφέρονται τα ακόλουθα:
1. Αναγκαιότητα ανάπτυξης ενός ολοκληρωμένου πλαισίου ενίσχυσης των δεξιοτήτων του ανθρώπινου δυναμικού στον τομέα της Τεχνητής Νοημοσύνης στην Υγεία. Η επιτυχής ενσωμάτωση εφαρμογών ΤΝ προϋποθέτει την κατάλληλη εκπαίδευση και συνεχή επιμόρφωση των επαγγελματιών υγείας, των διοικητικών στελεχών και του λοιπού προσωπικού, ώστε να μπορούν να αξιοποιούν τις νέες τεχνολογίες με ασφάλεια, υπευθυνότητα και αποτελεσματικότητα.
2. Η αξιοποίηση της Τεχνητής Νοημοσύνης έχει αποκλειστικά υποστηρικτικό χαρακτήρα και δεν υποκαθιστά σε καμία περίπτωση την επιστημονική κρίση, την επαγγελματική ευθύνη και τη λήψη αποφάσεων από τους επαγγελματίες υγείας.
3. Η αξιοποίηση εφαρμογών Τεχνητής Νοημοσύνης στον τομέα της Υγείας πραγματοποιείται στο πλαίσιο αυστηρών προδιαγραφών προστασίας των προσωπικών δεδομένων και ιδιαίτερα των δεδομένων υγείας. Απαιτείται η εφαρμογή κατάλληλων μηχανισμών ασφάλειας, διαφάνειας και ελέγχου όσον αφορά τη συλλογή, επεξεργασία, αποθήκευση και αξιοποίηση των δεδομένων από συστήματα ΤΝ.
4. Ενεργός συμμετοχή των επαγγελματιών υγείας και ιδιαίτερα των νοσηλευτών και μαιών στον σχεδιασμό και την εφαρμογή λύσεων ΤΝ.
Η ανάπτυξη και εισαγωγή εφαρμογών ΤΝ στο Σύστημα Υγείας πραγματοποιείται με ουσιαστική συμμετοχή των επαγγελματιών που θα τις χρησιμοποιούν στην καθημερινή πρακτική. Ειδικότερα, η συμμετοχή νοσηλευτών και μαιών είναι σημαντική, δεδομένου του άμεσου και συνεχούς ρόλου τους στην παροχή φροντίδας και στην επικοινωνία με τους ασθενείς.
5. Αξιοποίηση της ΤΝ για μείωση του διοικητικού φόρτου των επαγγελματιών υγείας. Ιδιαίτερη έμφαση θα μπορούσε να δοθεί σε εφαρμογές που αυτοματοποιούν ή υποστηρίζουν διοικητικές και επαναλαμβανόμενες εργασίες, χωρίς να επηρεάζουν την ασφάλεια της φροντίδας, με στόχο την εξοικονόμηση χρόνου και τη δυνατότητα των επαγγελματιών υγείας να αφιερώνουν περισσότερο χρόνο στην άμεση φροντίδα των ασθενών.
Closing comments from the German Medical Institute.
Offer of contribution
We offer the following without charge:
• Our clinical AI deployment lifecycle and local validation protocol, including the chest X-ray evaluation methodology and the Greek-language reference-standard problem and how we addressed it, as a candidate template for a national validation protocol.
• Participation in the drafting of the dedicated AI healthcare strategy and in the design of the healthcare regulatory sandbox, including the regulatory classification and conformity assessment questions raised in Comments 1 and 2.
• Our membership of the European Network of AI-Powered Advanced Screening Centres as a channel for exchange between the national programme and current European deployment practice.
If the Republic procures validation, conformity or advisory services in this area, we would tender for that work on the same terms as any other provider, and we distinguish that clearly from the contributions offered above.
We thank the National AI Taskforce and the Chief Scientist for the substantial document, and for a consultation process that invites this kind of detail. Our comments are offered in support of the Strategy’s direction and its ambition for Cyprus to be a credible and fast route to the European market for trustworthy health AI. We would welcome the opportunity to discuss any of them.
Comment 8 of 8 from the German Medical Institute
Comment 8: Define the workforce target and accredit clinical AI training through the professional bodies
Article / paragraph: Section 3.5, Priority Sector 3 (“By 2032, Cyprus aims for 50% of its medical workforce to be trained in AI-enabled practices”); Section 3.6.2 (Advanced and Sector-Specific Skills); Annex C, Healthcare and Life Sciences; Annex C, Education and Human Capital Development (FutureAI CY); Annex F.
Comment / Suggestion: Amend the workforce provisions to: (a) define “medical workforce” so that the 50% target is extended beyond physicians to the wider clinical workforce, including medical physicists, radiographers, nurses and laboratory scientists; (b) accredit clinical AI training as continuing professional development through the Cyprus Medical Association and the relevant professional bodies, so it carries professional recognition; and (c) structure it in three tiers: general clinical AI literacy for the whole workforce, a smaller cohort with deployment and evaluation competence, and a designated clinical AI lead in each institution.
Justification: As drafted the target cannot be measured, because the term “medical workforce” is not fully defined and because “trained in AI-enabled practices” has no stated competence standard.
The AI Act requires meaningful human oversight of high-risk systems, but this only applies when the overseeing clinician is competent to disagree with the system. They need to know its failure modes, to recognise when a case is outside its validated distribution, and to have the confidence to override it. That is a different competence from knowing how to use a tool, and it is what local validation, drift monitoring and post-deployment surveillance all require. A national programme that trains 50% of the workforce to use AI tools, without producing the smaller cohort that can evaluate and govern them, will have satisfied the target and not the underlying requirement.
We would add that the clinical workforce in AI-enabled care is not only physicians. In our own deployments, medical physicists and radiographers carry much of the evaluation and quality assurance work.
Comment 7 of 8 from the German Medical Institute
Comment 7: Specify a health-designated secure processing environment within the National AI Infrastructure
Article / paragraph: Section 3.7 (Infrastructure, Compute and Digital Sovereignty), particularly 3.7.2, 3.7.3 and 3.7.4; Section 3.7.5 (Integration with EuroHPC and the European AI Factory Ecosystem); Annex C, Healthcare and Life Sciences.
Comment / Suggestion: State that the National AI Infrastructure will include a health-designated secure processing environment, operating on the European Health Data Space model where data does not leave the environment and only results are exported. The infrastructure should be suitably sized for medical imaging, and available to hospitals, researchers and validation programmes under the Data Access Committee governance the Strategy already describes.
Justification: Health data cannot be served by a general-purpose allocation policy alone: it requires environments where the access controls, audit trails, residency guarantees and export restrictions are fundamental properties of the infrastructure. Sovereignty for health data is not a question of scale, but rather in which environment the data sits and who governs access.
Comment 6 of 8 from the German Medical Institute
Comment 6: Make interoperable digitalisation a dated obligation for all providers contracted to the General Healthcare System
Article / paragraph: Section 3.2.4 (Data by Design in Public Systems); Section 3.5, Priority Sector 3 (Secure National Health Data Repository); Annex C, Healthcare and Life Sciences; Section 5, item 3.
Comment / Suggestion: Introduce an explicit obligation, with a stated date and a phased schedule by provider size, for all healthcare providers contracted to the General Healthcare System (both public and private) to: (i) maintain structured electronic health records conforming to the European Electronic Health Record Exchange Format; and (ii) to transmit a defined minimum dataset to the National Health Data Repository. GHS contracting could be used as the enforcement mechanism.
Justification: The Strategy describes a Secure National Health Data Repository that consolidates data from hospitals and laboratories, but places no obligation on the institutions that hold this data. Contribution will therefore be provided by hospitals that are willing to do so, and the national repository will only represent whoever choses to participate. Any AI system trained or validated on it will inherit that bias.
Comment 5 of 8 from the German Medical Institute
Comment 5: Name disease registries as first deliverables of the National Health Data Repository
Article / paragraph: Section 3.5, Priority Sector 3 (Secure National Health Data Repository); Annex C, Healthcare and Life Sciences, “Implementation, evidence and compliance”; Section 3.2.1 (sectoral data spaces); Section 5, item 3.
Comment / Suggestion: Specify a national cancer registry and a national rare disease registry as first outputs of the Secure National Health Data Repository. Each registry should have an identified responsible body and alignment to the corresponding European standards and infrastructures.
Justification: The Secure National Health Data Repository is currently described by the data types it will consolidate (primary care, hospitals, laboratories, imaging, prescriptions) and not by any clinical product it will deliver. Disease registries are the natural first deliverable. They have a defined scope, an identifiable clinical owner, and an existing European reference framework. They are also where health AI development starts, because a curated registry with outcome data is a usable training and validation asset.
Comment 4 of 8 from the German Medical Institute
Comment 4: Recognise the European Network of AI-Powered Advanced Screening Centres in the international alignment provisions
Article / paragraph: Annex C, Healthcare and Life Sciences, “International alignment”.
Comment / Suggestion: Name the European Network of AI-Powered Advanced Screening Centres among the European initiatives in which Cyprus participates.
Justification: Section 3.12.2 commits Cyprus to active participation in European initiatives, and the Healthcare pillar’s international alignment section in Annex C refers to WHO guidance and European principles. It would be good to mention the European Commission’s network on AI-Powered Advanced Screening Centres, which is the country’s most concrete existing operational link into European health AI practice and in which three Cypriot organisations are already members. The network is where deployment experience, evaluation methods and failure modes are exchanged between the hospitals doing this work within Europe.
Comment 3 of 8 from the German Medical Institute
Comment 3: Establish a national clinical AI validation function and require local performance verification before deployment
Article / paragraph: Section 2.3.4 (Strengthening the International Position); Section 3.7.4 (Deployment Environments); Section 3.8.5 (National Testbeds); Annex C, Healthcare and Life Sciences, “Implementation, evidence and compliance”; Annex C, Entrepreneurship and Innovation (GHS health data sandbox).
Comment / Suggestion: Add to the Healthcare pillar a requirement that no AI system be deployed in a publicly funded Cyprus clinical setting without a documented local performance evaluation. This should be conducted on local patient data and assessed against local clinicians’ reports. This should be repeated at defined intervals thereafter. Designate a national clinical AI validation function to publish the protocol, maintain the evidence base and make results available across the health system. CE marking is necessary for deployment but is insufficient alone.
Justification: GMI can recommend this based on our own experience. In our chest X-ray programme we shortlisted candidate tools against published performance figures, then evaluated them on a consecutive sample of 731 local cases, using our radiologists’ original reports as the reference standard. Vendor-quoted metrics, obtained on the vendors’ test datasets, are not a reliable predictor of performance on a given hospital’s case mix. The evaluation changed which tool we selected. It is the single highest-value step in our deployment lifecycle and it cannot be substituted for with a CE mark. The CE mark certifies that a device meets its own intended-purpose claims, not that it performs on a particular population.
There is a specific Cypriot obstacle that all hospitals wanting to perform local validation will encounter. The clinicians’ reports are in Greek and the AI outputs are in English, so local validation first requires translation before the reports could be used as the ground truth. Every Cypriot institution deploying diagnostic AI will meet the same problem and solving it once nationally is cheaper than solving it repeatedly for each centre.
Comment 2 of 8 from the German Medical Institute
Comment 2: Correct the compliance timeline and bring the regulatory components of the healthcare AI strategy forward to 2027
Article / paragraph: Section 3.5, Priority Sector 3 (“A full-scale AI healthcare strategy is recommended for development by 2028”); Annex C, Healthcare and Life Sciences; Section 3.8.5 (National Testbeds); Section 5 (Immediate Steps); Annex A.
Comment / Suggestion: Bring forward the regulatory, validation and conformity components of the dedicated AI healthcare strategy from 2028 to 2027. In parallel, state in Section 3.8.5 that Cyprus will satisfy its obligation under Article 57 of the AI Act to have at least one AI regulatory sandbox operational – this could be a healthcare sandbox. The responsible body and the date should be named.
Justification: Since the Strategy was drafted, the dates for compliance have changed. Following adoption of the Digital Omnibus on AI by the European Parliament in June 2026 and the Council on 29 June 2026, the relevant dates are: Article 50 transparency obligations from 2 August 2026 (already in force); high-risk obligations for standalone Annex III systems from 2 December 2027; and high-risk obligations for AI embedded in regulated products from 2 August 2028. Separately, Member States must have at least one national AI regulatory sandbox in place by 2 August 2027.
We also add that the European Health Data Space Regulation (EU) 2025/327 applies from 26 March 2027, with cross-border exchange of imaging, laboratory results and discharge reports required by March 2031. It also requires each Member State to designate a national digital health authority and a health data access body. These obligations should be included in the Strategy’s timeline.
Comment 1 of 8 from the German Medical Institute
Comment 1: Name the Medical Device Regulation in the Healthcare pillar and in the European alignment provisions
Article / paragraph: Section 3.5, Priority Sector 3 (Healthcare and Life Sciences); Annex C, Healthcare and Life Sciences, “National frameworks and governance” and “International alignment”; Section 3.3.2 (Control Framework); Annex A (Alignment with European Legal and Policy Frameworks).
Comment / Suggestion: Add Regulation (EU) 2017/745 on medical devices (MDR) and Regulation (EU) 2017/746 on in vitro diagnostic medical devices (IVDR) to Annex A and to the Healthcare pillar’s governance provisions. State explicitly that AI intended for diagnosis, triage, treatment decision support or patient risk stratification is regulated as a medical device, that CE marking under the MDR is a precondition of clinical deployment, and that EU AI Act obligations attach on top of that classification (and not in place of it). Require that every AI initiative in the Healthcare pillar carries a documented regulatory classification at the point it enters the national portfolio. If medical device are introduced, there should be clear documentation about its class and conformity assessment route.
Justification: Under Rule 11 of Annex VIII to the MDR, software intended to provide information used to take decisions for diagnostic or therapeutic purposes is (at minimum) Class IIa. This rises to Class IIb where the decision may cause serious deterioration or require surgical intervention, and reaches Class III where it may cause death or irreversible deterioration. Applying that rule to the Strategy’s own intended infrastructures: (i) Intelligent Patient Triage and Care Navigation, which routes patients to care pathways including emergency services on the basis of clinical urgency, is not a low class device; (ii) Virtual AI Patient Orchestrator, which performs symptom reporting, risk alerts and referral, is also a medical device; (iii) the Socratic scaffolding will also be designing medical device diagnostic AI. Medical devices of Class IIa and above cannot be placed on the market without a notified body (self-declaration is not possible).
SUBMISSION TO THE PUBLIC CONSULTATION ON THE NATIONAL AI STRATEGY OF THE REPUBLIC OF CYPRUS 2032
Comments on the Healthcare and Life Sciences pillar
Submitted by: German Medical Institute (GMI), Limassol, Cyprus
Date: 27/08/2026
About the submitter
The German Medical Institute is a hospital in Limassol and one of three Cypriot member organisations of the European Network of AI-Powered Advanced Screening Centres, convened by the Artificial Intelligence in Health and Life Sciences unit of the European Commission’s DG CNECT, alongside the State Health Services Organisation with the University of Cyprus, and the Bank of Cyprus Oncology Centre. On 11 May 2026 we presented our clinical AI deployment methodology to that network.
We set out the following because several of the comments below rest on it:
• GMI completed full hospital digitisation at the end of 2026.
• Eight AI tools are in routine clinical use across radiotherapy, MRI, X-ray, nuclear medicine, dermatology and clinical document workflows, with further deployments in progress.
• Every deployment follows a structured lifecycle that includes a local retrospective evaluation on our own patients, our own images and our own clinicians’ reports before any clinical use.
• GMI is a partner in EU-funded work on the European Electronic Health Record Exchange Format (EEHRxF) and on cancer research data infrastructure under Horizon Mission Cancer.
Declaration of interest. Through the GMI Innovation Centre we provide clinical validation and EU market-entry pathway support to international health-AI developers. This currently spans six programmes with developers in India, the United States, France and South Korea. We would therefore have an interest in national work of this kind, and several recommendations below, if adopted, would create opportunities for which we and other Cypriot institutions would be candidates. We make them because we consider the underlying gaps material, and we have stated at the end of this submission what we are offering without charge and what we are not.
General remarks
The Healthcare and Life Sciences pillar identifies the problems well: fragmented data, capacity pressure, and the need for clinical decision support that augments rather than displaces clinical judgement. The commitments to HL7 FHIR, SNOMED CT and ICD, to European Health Data Space principles, to independent Data Access Committees, and to monitoring for bias and model drift are the correct foundations.
Our comments address one structural gap and seven consequences of it. The gap is that the Strategy governs healthcare AI almost entirely through the lens of the EU AI Act, which is mentioned throughout, and does not mention the Medical Device Regulation. For clinical AI, the Medical Device Regulation is the first step and the AI Act applies on top of it, not instead of it. Most of the flagship initiatives described in the Healthcare pillar are medical devices and thus the national programme should account for this.
ΣΧΟΛΙΑ ΕΠΙ ΤΗΣ ΕΘΝΙΚΗΣ ΣΤΡΑΤΗΓΙΚΗΣ ΤΕΧΝΗΤΗΣ ΝΟΗΜΟΣΥΝΗΣ 2032
1. Τεχνική ανακρίβεια στο ISO/IEC 42001
Σε δύο τουλάχιστον σημεία (ενότητες 3.13.1 και 3.11.2), η Στρατηγική παρουσιάζει το ISO/IEC 42001 ως πρότυπο διαχείρισης κινδύνου (risk management). Δεν είναι. Το ISO/IEC 42001 αφορά το Σύστημα Διαχείρισης ΤΝ (AI Management System – AIMS), ενώ το ISO/IEC 23894 παρέχει καθοδήγηση ειδικά για τη διαχείριση κινδύνων ΤΝ (AI risk management). Η διάκριση είναι σημαντική και θα πρέπει να αποτυπωθεί σωστά στην τελική Στρατηγική.
2. Η ήδη υπάρχουσα ΤΝ παραμένει αόρατη
Ο AI Use Case Lifecycle (Annex B) και το AIREG δίνουν έμφαση κυρίως στη διακυβέρνηση και καταγραφή νέων ή υπό ανάπτυξη συστημάτων. Χρειάζεται όμως σαφέστερη πρόβλεψη και για την ΤΝ που ήδη χρησιμοποιείται, συχνά ενσωματωμένη σε ERP, CRM, SaaS ή διαδικασίες αυτοματοποιημένης λήψης αποφάσεων.
Προτείνεται ένα συνεχώς ενημερωμένο μητρώο για όλα τα συστήματα ΤΝ στον δημόσιο τομέα, περιλαμβανομένων third-party και embedded AI, με σαφή καταγραφή του υπεύθυνου, του σκοπού χρήσης, του provider/model και του επιπέδου κινδύνου και αυτονομίας.
Διαφορετικά, υπάρχει κίνδυνος να δημιουργήσουμε ένα ισχυρό πλαίσιο για το AI που έρχεται, χωρίς πλήρη εικόνα του AI που ήδη χρησιμοποιείται.
3. Το Agentic AI χρειάζεται δικό του governance layer
Η Στρατηγική αναφέρεται σε agentic AI, multi-agent systems, A2A, MCP και OASF, χωρίς όμως να ορίζει επαρκώς τι επιτρέπεται να κάνει ένα τέτοιο σύστημα. Χρειάζονται σαφείς κανόνες για permissions, tool access, memory, logging, human override και safe termination.
Το Control Framework (Annex B) χρειάζεται να επεκταθεί ώστε να καλύπτει συστήματα που αναθέτουν υπο-εργασίες και εκτελούν ενέργειες αυτόνομα. Σε εφαρμογές όπως AI Judge, Virtual Patient Orchestrator ή agentic copilots στη ναυτιλία, το κρίσιμο ερώτημα δεν είναι μόνο «τι παράγει το σύστημα», αλλά «τι του επιτρέπεται να κάνει».
4. Ο AI Officer δεν μπορεί να είναι ταυτόχρονα υλοποιητής και ελεγκτής
Το Annex E αναθέτει στον AI Officer αρμοδιότητες τόσο στην υλοποίηση όσο και στη διαχείριση κινδύνου. Αυτό δημιουργεί πιθανή σύγκρουση ρόλων. Η υλοποίηση και η ανεξάρτητη αξιολόγηση ενός συστήματος θα πρέπει να παραμένουν διακριτές λειτουργίες, ώστε να αποφεύγεται πιθανή σύγκρουση συμφερόντων.
Παράλληλα, η αναφορά ότι «deep technical expertise is not always required» χρειάζεται επανεξέταση, ιδιαίτερα για συστήματα υψηλού κινδύνου κατά το EU AI Act. Χρειάζεται ελάχιστο competency framework ανά επίπεδο κινδύνου, διαφανής διαδικασία επιλογής και, όπου υπάρχει ήδη η απαιτούμενη τεχνογνωσία στον δημόσιο τομέα, αξιοποίηση υφιστάμενου προσωπικού χωρίς κατ’ ανάγκη δημιουργία νέων θέσεων.
5. Το human oversight χρειάζεται ορισμό στην πράξη και ανεξάρτητο έλεγχο για κρίσιμα συστήματα
Η Στρατηγική δίνει σωστά έμφαση στο human oversight, χωρίς όμως να ορίζει πότε αυτό είναι ουσιαστικό στην πράξη. Ο άνθρωπος που φέρει την ευθύνη πρέπει να έχει τη γνώση, την πληροφόρηση, τον χρόνο και κυρίως την εξουσία να αμφισβητήσει, να ανατρέψει ή να σταματήσει μια ενέργεια του συστήματος. Διαφορετικά, το oversight κινδυνεύει να παραμείνει τυπικό.
Για critical ή high-impact συστήματα, θα πρέπει επίσης να προβλέπεται ανεξάρτητη αξιολόγηση, ώστε ο έλεγχος να μην εξαρτάται αποκλειστικά από τον προμηθευτή ή τον φορέα υλοποίησης.
6. Ετοιμότητα για σημαντικά πιο προηγμένα συστήματα ΤΝ στον ορίζοντα του 2032
Η ενότητα 3.13.4 αναφέρεται σε «mechanisms to adapt», χωρίς όμως να καθορίζει συγκεκριμένους μηχανισμούς για σημαντικές αλλαγές στις δυνατότητες της ΤΝ. Δεν χρειάζεται η Στρατηγική να προβλέψει αν ή πότε θα υπάρξει AGI. Με ορίζοντα όμως το 2032, χρειάζεται να είναι έτοιμη για σημαντικά πιο ικανά ή αυτόνομα συστήματα.
Προτείνεται capability-triggered review, με προκαθορισμένα thresholds που θα ενεργοποιούν αναθεώρηση όταν μεταβάλλονται ουσιαστικά οι δυνατότητες ή η αυτονομία των συστημάτων, όταν συμβαίνει σοβαρό AI incident ή όταν αλλάζει σημαντικά το regulatory environment. Ένας μόνο προγραμματισμένος κύκλος αναθεώρησης δεν αρκεί για μια τεχνολογία που εξελίσσεται με αυτή την ταχύτητα.
7. Εκπαίδευση: από τη χρήση της ΤΝ στην ανθρώπινη κρίση
Το CALF, το EPVL και το Socratic Scaffolding κινούνται στη σωστή κατεύθυνση. Θα έδινα όμως μεγαλύτερη έμφαση στην ανθρώπινη αυτενέργεια (Human Agency). Δεν αρκεί ο μαθητής να γνωρίζει πώς να χρησιμοποιεί την ΤΝ ή να υπάρχει ένας εκπαιδευτικός ως φίλτρο. Πρέπει σταδιακά να μάθει ο ίδιος να ορίζει τον σκοπό, να καθοδηγεί το σύστημα, να ζητά τεκμήρια, να επαληθεύει πηγές, να αναγνωρίζει αβεβαιότητα και να αμφισβητεί ακόμη και μια πολύ πειστική απάντηση.
Όσο καλύτερα γίνονται τα συστήματα ΤΝ, τόσο σημαντικότερη γίνεται αυτή η ικανότητα. Ο στόχος δεν πρέπει να είναι μόνο Human-in-the-loop, αλλά Human-in-command: ο μαθητής να μπορεί να χρησιμοποιεί την ΤΝ χωρίς να της παραδίδει την κρίση του. Αυτή είναι δεξιότητα που θα παραμείνει σημαντική ανεξάρτητα από τα μοντέλα και τις τεχνολογίες που θα υπάρχουν το 2032.
8. Τα KPIs δεν μπορούν να παραμείνουν «sample»
Το Annex F χαρακτηρίζει το πλαίσιο των KPIs ως «sample». Αυτό χρειάζεται αλλαγή. Όταν η Στρατηγική θέτει συγκεκριμένους στόχους, όπως 75% AI adoption ή 10–20% μείωση κατανάλωσης καυσίμων στη ναυτιλία, πρέπει να είναι εξίσου συγκεκριμένος και ο τρόπος μέτρησής τους.
Κάθε βασικό KPI χρειάζεται baseline, σαφή μεθοδολογία μέτρησης, υπεύθυνο φορέα και ετήσια δημόσια αναφορά προόδου. Διαφορετικά, στο τέλος θα γνωρίζουμε τους στόχους που τέθηκαν, αλλά όχι με αντικειμενικό τρόπο αν επιτεύχθηκαν. Η ευελιξία είναι χρήσιμη στην υλοποίηση, όχι στη λογοδοσία.
9. Vendor lock-in και digital sovereignty
Η Στρατηγική μιλά για digital sovereignty. Στην πράξη, όμως, το Δημόσιο πρέπει να μπορεί να αλλάξει AI provider χωρίς να εγκλωβίζεται σε μία εταιρεία ή πλατφόρμα.
Χρειάζονται σαφείς απαιτήσεις για portability, interoperability και vendor exit, ώστε δεδομένα, μοντέλα και κρίσιμες λειτουργίες να μπορούν, όπου είναι τεχνικά εφικτό, να μεταφερθούν σε άλλον πάροχο. Για μια μικρή αγορά, η εξάρτηση από έναν πάροχο χωρίς πρακτική δυνατότητα εξόδου αποτελεί στρατηγικό κίνδυνο.
10. Το «augment, not replace» πρέπει να μπορεί να μετρηθεί
Η αρχή «augment, not replace» είναι σωστή ως κατεύθυνση, αλλά χρειάζεται μηχανισμό παρακολούθησης. Θα πρέπει να καταγράφεται ανά τομέα ποιες θέσεις ή καθήκοντα επηρεάζονται από την ΤΝ και πόσοι εργαζόμενοι επανακαταρτίζονται (re-skilling) ή μετακινούνται σε νέους ρόλους.
Δεν αρκεί να λέμε ότι η ΤΝ θα ενισχύσει τον άνθρωπο. Πρέπει να μπορούμε και να το αποδεικνύουμε.
11. Κάθε δημόσιος οργανισμός που χρησιμοποιεί ΤΝ πρέπει να έχει δική του AI Policy
Η Στρατηγική θα ήταν χρήσιμο να προβλέπει ότι κάθε δημόσιος οργανισμός που αναπτύσσει ή χρησιμοποιεί ΤΝ διαθέτει γραπτή AI Policy. Η πολιτική αυτή πρέπει να καθορίζει τουλάχιστον πού και για ποιο σκοπό επιτρέπεται η χρήση ΤΝ, ποια είναι τα όρια, ποιος έχει την ευθύνη και ποιος λογοδοτεί.
Αυτό συνδέεται και με το ISO/IEC 42001, το οποίο η ίδια η Στρατηγική επικαλείται και προβλέπει documented AI Policy στο πλαίσιο ενός AI Management System. Χωρίς σαφή πολιτική σε επίπεδο οργανισμού, οι υπόλοιποι μηχανισμοί governance δεν έχουν κοινή βάση εφαρμογής.
12. Η ικανότητα κατεύθυνσης της ΤΝ χρειάζεται να ενταχθεί στις δεξιότητες
Η Στρατηγική προβλέπει agentic AI, multi-agent systems και σύνθετες εφαρμογές ΤΝ σε κρίσιμους τομείς. Δεν δίνεται όμως αντίστοιχη έμφαση στην ικανότητα του ανθρώπου να κατευθύνει αποτελεσματικά αυτά τα συστήματα: να ορίζει σκοπό, να παρέχει το κατάλληλο context, να θέτει περιορισμούς και να αξιολογεί αν το αποτέλεσμα ανταποκρίνεται στην πρόθεσή του.
Δεξιότητες όπως prompt engineering και context engineering, ανεξάρτητα από το πώς θα ονομάζονται στο μέλλον, θα πρέπει να ενταχθούν στα σχετικά εκπαιδευτικά και επαγγελματικά πλαίσια. Όσο πιο ικανά γίνονται τα συστήματα ΤΝ, τόσο πιο σημαντική γίνεται η ικανότητα του ανθρώπου να τους δίνει σωστή κατεύθυνση.
13. Η κυβερνοασφάλεια πρέπει να ενσωματωθεί στον κύκλο ζωής κάθε συστήματος ΤΝ
Η Στρατηγική δίνει σημαντική έμφαση στην κυβερνοασφάλεια, αλλά χρειάζεται σαφέστερη σύνδεσή της με τον AI Use Case Lifecycle (Annex B). Κάθε σύστημα ΤΝ, ιδιαίτερα σε κρίσιμες λειτουργίες, θα πρέπει να περνά υποχρεωτικό security assessment πριν τεθεί σε παραγωγική λειτουργία και να επανελέγχεται όταν αλλάζει ουσιαστικά.
Ιδιαίτερη πρόβλεψη χρειάζεται για agentic AI, όπου εμφανίζονται νέοι κίνδυνοι όπως prompt injection, tool poisoning και memory manipulation. Η κυβερνοασφάλεια δεν πρέπει να λειτουργεί παράλληλα με το AI governance, αλλά να αποτελεί μέρος του ίδιου του κύκλου ζωής του συστήματος.